nerdexam
(ISC)2

CGRC · Question #296

From a system authorization perspective, why are potential system software patches tested prior to deployment? Response:

The correct answer is D. To identify potential security impacts that may be caused by the patch. Patches are tested before deployment to identify any potential adverse effects on system functionality, stability, or security posture, preventing new vulnerabilities or operational disruptions.

Implementation of Security and Privacy Controls

Question

From a system authorization perspective, why are potential system software patches tested prior to deployment? Response:

Options

  • ATo ensure that the system documentation is current with the changes
  • BTo support long-term investments
  • CTo comply with Public Law 107-347
  • DTo identify potential security impacts that may be caused by the patch

How the community answered

(26 responses)
  • B
    4% (1)
  • C
    4% (1)
  • D
    92% (24)

Why each option

Patches are tested before deployment to identify any potential adverse effects on system functionality, stability, or security posture, preventing new vulnerabilities or operational disruptions.

ATo ensure that the system documentation is current with the changes

While documentation updates are necessary after changes, ensuring documentation currency is a secondary task and not the primary reason for patch testing from a security impact perspective.

BTo support long-term investments

Supporting long-term investments is a broad organizational goal and not the specific technical reason for testing patches before deployment.

CTo comply with Public Law 107-347

Public Law 107-347 mandates information security, but the specific technical reason for testing patches is to identify security impacts, not merely to comply with a law.

DTo identify potential security impacts that may be caused by the patchCorrect

Testing software patches prior to deployment is crucial from a system authorization perspective to identify unintended consequences, including new security vulnerabilities, conflicts with existing configurations, or regressions. This proactive testing ensures the patch effectively addresses its intended vulnerability without introducing new risks or instability, maintaining the system's authorized security state.

Concept tested: Patch management best practices - security impact analysis

Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-40r4.pdf

Topics

#Patch management#Security testing#Vulnerability management#Impact assessment

Community Discussion

No community discussion yet for this question.

Full CGRC Practice