nerdexam
(ISC)2

CISSP · Question #575

Directive controls are a form of change management policy and procedures. Which of the following subsections are recommended as part of the change management process?

The correct answer is A. Build and test. Change management processes follow a structured lifecycle that includes phases such as build and test before implementing changes in production. This ensures changes are validated before deployment.

Submitted by yasin.bd· Mar 5, 2026Software Development Security

Question

Directive controls are a form of change management policy and procedures. Which of the following subsections are recommended as part of the change management process?

Options

  • ABuild and test
  • BImplement security controls
  • CCategorize Information System (IS)
  • DSelect security controls

How the community answered

(46 responses)
  • A
    91% (42)
  • B
    2% (1)
  • C
    4% (2)
  • D
    2% (1)

Why each option

Change management processes follow a structured lifecycle that includes phases such as build and test before implementing changes in production. This ensures changes are validated before deployment.

ABuild and testCorrect

Build and test is a recognized subsection of the change management process, where proposed changes are constructed in a controlled environment and validated before production deployment. This phase ensures that changes do not introduce unintended vulnerabilities or failures, aligning with standard change management frameworks such as ITIL and NIST guidelines. It is a core step in directive controls that govern how changes are safely introduced into an environment.

BImplement security controls

Implementing security controls is part of the Risk Management Framework (RMF) or a security control implementation process, not a subsection of the change management process itself.

CCategorize Information System (IS)

Categorizing the Information System is the first step of the NIST Risk Management Framework (RMF), specifically under FIPS 199 and NIST SP 800-60, and is not a subsection of change management.

DSelect security controls

Selecting security controls is Step 2 of the NIST RMF process (NIST SP 800-53), which is part of the security authorization framework, not a component of change management procedures.

Concept tested: Change management process subsections and lifecycle phases

Source: https://csrc.nist.gov/publications/detail/sp/800-128/final

Topics

#Change management#Directive controls#Build and test#Software development

Community Discussion

No community discussion yet for this question.

Full CISSP Practice