CISM · Question #323
The PRIMARY benefit of integrating information security activities into change management processes is to:
The correct answer is C. ensure required controls are included in changes. Integrating information security into change management ensures that security controls are evaluated and embedded before changes go live - catching gaps at design time rather than after deployment. Option A is too narrow; while collusion and compliance are real concerns, they…
Question
The PRIMARY benefit of integrating information security activities into change management processes is to:
Options
- Aprotect the business from collusion and compliance threats.
- Bprovide greater accountability for security-related changes in the business.
- Censure required controls are included in changes.
- Dprotect the organization from unauthorized changes.
How the community answered
(13 responses)- B8% (1)
- C92% (12)
Explanation
Integrating information security into change management ensures that security controls are evaluated and embedded before changes go live - catching gaps at design time rather than after deployment. Option A is too narrow; while collusion and compliance are real concerns, they are not the primary driver of this integration. Option B (accountability) is a side effect, not the core purpose - accountability mechanisms exist independently of change management. Option D (preventing unauthorized changes) describes access control and authorization processes, which are separate from integrating security activities into change management workflows.
Memory tip: Think "security by design, not by accident." Change management integration is about building security in, not bolting it on afterward - that maps directly to ensuring controls are included in changes (C).
Topics
Community Discussion
No community discussion yet for this question.