nerdexam
Isaca

CISM · Question #403

Which of the following should be the information security manager's FIRST step to address a trend of new vulnerabilities appearing in an internally-developed application?

The correct answer is D. Assess the effectiveness of the existing change management process.. The first step should be to evaluate the change management process to determine if security controls are being properly integrated into the development lifecycle. If vulnerabilities are consistently emerging, there may be gaps in secure coding practices, testing, or review proces

Submitted by marco_it· Apr 18, 2026Information Security Program Development and Management

Question

Which of the following should be the information security manager's FIRST step to address a trend of new vulnerabilities appearing in an internally-developed application?

Options

  • AForm a security committee with mandatory developer participation.
  • BAdd security requirements to developer job descriptions.
  • CConduct penetration testing on the production application.
  • DAssess the effectiveness of the existing change management process.

How the community answered

(19 responses)
  • A
    5% (1)
  • B
    5% (1)
  • C
    11% (2)
  • D
    79% (15)

Explanation

The first step should be to evaluate the change management process to determine if security controls are being properly integrated into the development lifecycle. If vulnerabilities are consistently emerging, there may be gaps in secure coding practices, testing, or review processes. Identifying weaknesses in change management helps ensure that security is embedded in development and deployment processes, reducing future vulnerabilities.

Topics

#Change Management#SDLC Security#Vulnerability Management#Process Effectiveness

Community Discussion

No community discussion yet for this question.

Full CISM Practice