CISSP · Question #680
What does the change management process entail?
The correct answer is D. Identify vulnerabilities. Change management is a structured process for controlling modifications to IT systems, and a core component is identifying vulnerabilities that changes may introduce or that necessitate the change.
Question
What does the change management process entail?
Options
- AObtain information security management approval.
- BMaintain the integrity of the application.
- CObtain feedback before implementation.
- DIdentify vulnerabilities.
How the community answered
(28 responses)- A4% (1)
- B4% (1)
- C11% (3)
- D82% (23)
Why each option
Change management is a structured process for controlling modifications to IT systems, and a core component is identifying vulnerabilities that changes may introduce or that necessitate the change.
Obtaining information security management approval may be one procedural step in some organizations, but it is not the defining or comprehensive description of what change management entails as a process.
Maintaining the integrity of the application is a broader security objective and a desired outcome, not a specific activity that defines the change management process itself.
Obtaining feedback before implementation may be part of a change advisory board (CAB) review, but it is not the primary or defining element that characterizes what change management entails.
Change management entails identifying vulnerabilities as part of evaluating the risk and impact of proposed changes to systems or applications. By identifying vulnerabilities, organizations can determine whether a change is necessary to remediate a security weakness and assess what new risks the change itself might introduce, making it a foundational step in the process.
Concept tested: Change management process and vulnerability identification
Source: https://www.nist.gov/publications/guide-enterprise-patch-management-planning-preventive-maintenance-software
Topics
Community Discussion
No community discussion yet for this question.