Certified Information Systems Security Professional CISSP · Free Practice Question Medium

Question 119

You are the Chief Information Security Officer (CISO) at a large multinational corporation. Your corporation is currently revamping its IT systems, requiring a lot of changes across multiple departments. These changes include software updates, server additions, configuration changes, and new security measures. You need to ensure that these changes are managed effectively to prevent disruptions and ensure system stability and security. In order to manage these changes effectively, what should be your primary approach?
  • A Prioritize changes based on their urgency and importance and implement them in a first-come-first-serve manner.
  • B Allow individual department heads to manage and implement changes in their respective departments, based on their understanding and needs.
  • C Establish a formalized change management process where each proposed change is thoroughly evaluated, justified, tested, and approved before being implemented.
  • D Implement the changes immediately as they come to avoid backlogs and ensure the IT systems are up-to-date as soon as possible.
Reveal correct answer

Correct answer: C

Explanation

The correct answer: Establishing a formalized change management process is the most effective way to handle changes in an IT environment. This process involves evaluating each proposed change for its necessity, potential benefits, and potential risks. The changes are then justified, explaining why they are necessary and how they will improve the system. Changes are tested in a controlled environment before being implemented to understand their impact and rectify any unforeseen issues. Finally, they must be approved by relevant authorities to ensure transparency and oversight. This process ensures that changes do not disrupt system operations or security and are beneficial to the organization. The incorrect answers: Implementing changes immediately can lead to significant system instability and potential security issues. Without a thorough evaluation and testing process, changes can have unforeseen impacts on the system and may even introduce new vulnerabilities or incompatibilities. Prioritizing changes based on urgency and importance and implementing them in a first-come-first-serve manner can result in lesser important but high-risk changes being implemented without thorough testing and approval, potentially introducing system instability or vulnerabilities. Allowing individual department heads to manage and implement changes can lead to inconsistent change management practices across the organization. This could result in communication gaps, inconsistency in system stability and security, and an overall reduction in system efficiency and effectiveness.

Discussion

Think the marked answer is wrong, or have a better explanation? Share it below — comments appear after review.

You must be logged in to post a comment.

Preparing For

Your Certification?

255+ certifications
Detailed explanations
Free PDF samples

Has All The Questions You Need