CISM · Question #18
A software vendor has announced a zero-day vulnerability that exposes an organization's critical business systems. The vendor has released an emergency patch. Which of the following should be the…
The correct answer is A. Ability to test the patch prior to deployment. The primary concern for an information security manager during an emergency patch deployment for a zero-day vulnerability is ensuring the patch does not introduce new instability or issues.
Question
A software vendor has announced a zero-day vulnerability that exposes an organization’s critical business systems. The vendor has released an emergency patch. Which of the following should be the information security manager’s PRIMARY concern?
Options
- AAbility to test the patch prior to deployment
- BAdequacy of the incident response plan
- CAvailability of resources to implement controls
- DDocumentation of patching procedures
How the community answered
(18 responses)- A83% (15)
- B6% (1)
- C11% (2)
Why each option
The primary concern for an information security manager during an emergency patch deployment for a zero-day vulnerability is ensuring the patch does not introduce new instability or issues.
While immediate deployment might seem critical for a zero-day, deploying an untested emergency patch without proper validation can introduce severe system instability, operational disruptions, or new vulnerabilities. The primary concern is balancing the need for speed with the imperative to maintain system stability and functionality, necessitating at least minimal testing.
Adequacy of the incident response plan is important, but the immediate concern during a *patch deployment* is the patch itself and its impact, assuming the zero-day *has* been found.
Availability of resources to implement controls is a logistical concern, but the technical validity and safety of the patch itself take precedence over resource allocation during critical decision-making.
Documentation of patching procedures is an administrative task that follows or runs concurrently with the actual patch deployment, not the primary concern during an emergency.
Concept tested: Emergency patch management considerations
Source: https://learn.microsoft.com/en-us/windows/security/threat-protection/windows-security-baselines/patch-management-process
Topics
Community Discussion
No community discussion yet for this question.