CGRC · Question #166
The use of automation to manage changes to the information system or its environment of operation facilitates Response:
The correct answer is C. Remediation plans. Automation in change management significantly aids in the implementation and tracking of remediation plans by ensuring that security deficiencies are addressed systematically and consistently across the information system. It streamlines the process of applying fixes and…
Question
The use of automation to manage changes to the information system or its environment of operation facilitates Response:
Options
- ASecurity impact analysis
- BPlan of actions and milestones
- CRemediation plans
- DSecurity control assessments
How the community answered
(60 responses)- A3% (2)
- B2% (1)
- C90% (54)
- D5% (3)
Why each option
Automation in change management significantly aids in the implementation and tracking of remediation plans by ensuring that security deficiencies are addressed systematically and consistently across the information system. It streamlines the process of applying fixes and verifying their deployment.
Security impact analysis is a preliminary step to assess the potential security implications of a proposed change, which is a decision-making process, not directly facilitated by the automation of the change itself.
A Plan of Actions and Milestones (POA&M) is a document that tracks identified weaknesses and planned corrective actions, while automation facilitates the execution of those actions, not the creation of the POA&M itself.
Automation to manage changes helps implement remediation plans by systematically applying patches, configuration changes, or other fixes across systems, reducing manual errors and increasing efficiency. While automation can touch on all these areas, its direct impact on executing corrective actions identified in remediation plans is particularly strong. For instance, automated patching systems directly address vulnerabilities identified in remediation plans.
Security control assessments are evaluations of the effectiveness of security controls, often involving manual or semi-manual review, and while automation can support some aspects, it doesn't facilitate the assessment itself in the same direct way it enables remediation.
Concept tested: Automation in change management and security
Source: https://csrc.nist.gov/glossary/term/remediation
Topics
Community Discussion
No community discussion yet for this question.