ExamGecko
Question list
Search
Search

Question 7 - CISM discussion

Report
Export

Which of the following change management procedures is MOST likely to cause concern to the information security manager?

A.
Fallback processes are tested the weekend before changes are made
Answers
A.
Fallback processes are tested the weekend before changes are made
B.
Users are not notified of scheduled system changes
Answers
B.
Users are not notified of scheduled system changes
C.
A manual rather than an automated process is used to compare program versions.
Answers
C.
A manual rather than an automated process is used to compare program versions.
D.
The development manager migrates programs into production
Answers
D.
The development manager migrates programs into production
Suggested answer: D

Explanation:

The change management procedure that is MOST likely to cause concern to the information security manager is the development manager migrating programs into production, because it involves a high-risk activity that could compromise the confidentiality, integrity, and availability of the information systems and data. Migrating programs into production without proper testing, validation, and approval could introduce errors, vulnerabilities, or conflicts that could affect the performance, functionality, or security of the systems.Fallback processes are tested the weekend before changes are made, users are not notified of scheduled system changes, and a manual rather than an automated process is used to compare program versions are all acceptable change management procedures that do not pose significant risks to the information security manager.Reference= CISM Review Manual, 16th Edition, page 3121; CISM Review Questions, Answers & Explanations Manual, 10th Edition, page 1522

asked 01/10/2024
Tym Dom
41 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first