nerdexam
Isaca

CISM · Question #641

During an information security audit, it was determined that IT staff did not follow the established standard when configuring and managing IT systems. Which of the following is the BEST way to…

The correct answer is D. Implementing a strict change control process. Implementing a strict change control process (D) directly addresses the root cause: IT staff were not following established standards when configuring and managing systems. A change control process enforces documented, reviewed, and approved procedures for every configuration…

Submitted by jian89· Apr 18, 2026Information Security Governance

Question

During an information security audit, it was determined that IT staff did not follow the established standard when configuring and managing IT systems. Which of the following is the BEST way to prevent future occurrences?

Options

  • AProviding annual information security awareness training
  • BConducting periodic vulnerability scanning
  • CUpdating configuration baselines
  • DImplementing a strict change control process

How the community answered

(56 responses)
  • A
    4% (2)
  • B
    7% (4)
  • C
    16% (9)
  • D
    73% (41)

Explanation

Implementing a strict change control process (D) directly addresses the root cause: IT staff were not following established standards when configuring and managing systems. A change control process enforces documented, reviewed, and approved procedures for every configuration change, creating accountability and a paper trail that prevents unauthorized or non-compliant modifications.

  • A (Annual security awareness training) targets general security behaviors across all staff, not the specific procedural compliance issue of IT administrators deviating from configuration standards - training frequency also isn't the gap here.
  • B (Periodic vulnerability scanning) detects weaknesses after the fact but does nothing to enforce process compliance before or during configuration changes.
  • C (Updating configuration baselines) assumes the baselines themselves are wrong - but the audit found staff weren't following existing standards, so updating the baselines doesn't solve non-compliance.

Memory tip: When an audit finds people bypassing a process, the fix is a control that enforces the process - think "control the change, control the behavior." Change control = enforced compliance. Awareness training = knowledge gap fix (use it when the problem is ignorance, not non-adherence).

Topics

#Change Control#Configuration Management#Compliance#Preventive Controls

Community Discussion

No community discussion yet for this question.

Full CISM Practice