nerdexam
(ISC)2

CGRC · Question #530

Which of the following processes has the goal to ensure that any change does not lead to reduced or compromised security? Response:

The correct answer is A. Change control management. Change control management is the process specifically designed to ensure that all changes to an information system are systematically reviewed, approved, and implemented in a way that prevents the reduction or compromise of security.

Compliance Maintenance

Question

Which of the following processes has the goal to ensure that any change does not lead to reduced or compromised security? Response:

Options

  • AChange control management
  • BSecurity management
  • CConfiguration management
  • DRisk management

How the community answered

(30 responses)
  • A
    87% (26)
  • B
    10% (3)
  • C
    3% (1)

Why each option

Change control management is the process specifically designed to ensure that all changes to an information system are systematically reviewed, approved, and implemented in a way that prevents the reduction or compromise of security.

AChange control managementCorrect

Change control management is the formal process that governs all modifications to an IT system or its environment. Its primary objective, especially from a security perspective, is to meticulously evaluate the security implications of every proposed change and ensure that only authorized, tested, and secure changes are deployed, thereby preventing unintended security vulnerabilities or degradation.

BSecurity management

Security management is a broad discipline that encompasses all security activities, of which change control is a specific part, but it's not the process specifically focused on managing individual changes.

CConfiguration management

Configuration management focuses on maintaining the consistency of a system's configuration over time, including security baselines, but change control is the process that enables changes to that configuration in a controlled manner.

DRisk management

Risk management is the overarching process of identifying, assessing, and mitigating risks. While change control is a risk mitigation strategy for changes, it is not the umbrella term for managing all changes to security.

Concept tested: Purpose of change control management for security

Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-128.pdf

Topics

#Change Management#Security Controls#Configuration Management

Community Discussion

No community discussion yet for this question.

Full CGRC Practice