nerdexam
(ISC)2

CGRC · Question #166

The use of automation to manage changes to the information system or its environment of operation facilitates Response:

The correct answer is C. Remediation plans. Automation in change management significantly aids in the implementation and tracking of remediation plans by ensuring that security deficiencies are addressed systematically and consistently across the information system. It streamlines the process of applying fixes and…

Implementation of Security and Privacy Controls

Question

The use of automation to manage changes to the information system or its environment of operation facilitates Response:

Options

  • ASecurity impact analysis
  • BPlan of actions and milestones
  • CRemediation plans
  • DSecurity control assessments

How the community answered

(60 responses)
  • A
    3% (2)
  • B
    2% (1)
  • C
    90% (54)
  • D
    5% (3)

Why each option

Automation in change management significantly aids in the implementation and tracking of remediation plans by ensuring that security deficiencies are addressed systematically and consistently across the information system. It streamlines the process of applying fixes and verifying their deployment.

ASecurity impact analysis

Security impact analysis is a preliminary step to assess the potential security implications of a proposed change, which is a decision-making process, not directly facilitated by the automation of the change itself.

BPlan of actions and milestones

A Plan of Actions and Milestones (POA&M) is a document that tracks identified weaknesses and planned corrective actions, while automation facilitates the execution of those actions, not the creation of the POA&M itself.

CRemediation plansCorrect

Automation to manage changes helps implement remediation plans by systematically applying patches, configuration changes, or other fixes across systems, reducing manual errors and increasing efficiency. While automation can touch on all these areas, its direct impact on executing corrective actions identified in remediation plans is particularly strong. For instance, automated patching systems directly address vulnerabilities identified in remediation plans.

DSecurity control assessments

Security control assessments are evaluations of the effectiveness of security controls, often involving manual or semi-manual review, and while automation can support some aspects, it doesn't facilitate the assessment itself in the same direct way it enables remediation.

Concept tested: Automation in change management and security

Source: https://csrc.nist.gov/glossary/term/remediation

Topics

#Automation#Change Management#Remediation#Control Implementation

Community Discussion

No community discussion yet for this question.

Full CGRC Practice