nerdexam
Isaca

CISM · Question #670

Which of the following is the BEST way to integrate information security into the organization's change management life cycle?

The correct answer is A. Ensure proposed changes include information security requirements prior to approval. Integrating information security requirements into proposed changes before approval ensures that risks are identified and mitigated early in the change management life cycle, promoting secure implementation from the outset.

Submitted by lars.no· Apr 18, 2026Information Security Program Development and Management

Question

Which of the following is the BEST way to integrate information security into the organization’s change management life cycle?

Options

  • AEnsure proposed changes include information security requirements prior to approval.
  • BInclude information security representation on the change advisory board.
  • CEnsure the change advisory board includes members from the business.
  • DInclude change management representation on the information security steering committee.

How the community answered

(40 responses)
  • A
    50% (20)
  • B
    15% (6)
  • C
    28% (11)
  • D
    8% (3)

Explanation

Integrating information security requirements into proposed changes before approval ensures that risks are identified and mitigated early in the change management life cycle, promoting secure implementation from the outset.

Topics

#Change Management#Security Integration#Process Integration#Security Program Management

Community Discussion

No community discussion yet for this question.

Full CISM Practice