ExamGecko
Question list
Search
Search

Question 331 - CISM discussion

Report
Export

A daily monitoring report reveals that an IT employee made a change to a firewall rule outside of the change control process. The information security manager's FIRST step in addressing the issue should be to:

A.
require that the change be reversed
Answers
A.
require that the change be reversed
B.
review the change management process
Answers
B.
review the change management process
C.
perform an analysis of the change
Answers
C.
perform an analysis of the change
D.
report the event to senior management
Answers
D.
report the event to senior management
Suggested answer: C

Explanation:

Performing an analysis of the change is the first step in addressing the issue of an IT employee making a change to a firewall rule outside of the change control process because it helps to understand the reason, impact, and risk of the change and to decide whether to approve, reject, or reverse it. Requiring that the change be reversed is not the first step because it may cause more disruption or damage without proper analysis and testing. Reviewing the change management process is not the first step because it does not address the specific issue or incident at hand, but rather focuses on improving the process for future changes. Reporting the event to senior management is not the first step because it does not resolve the issue or incident, but rather escalates it without sufficient information or recommendation.

Reference: https://www.isaca.org/resources/isaca-journal/issues/2018/volume-3/change-management-in-the-age-of-digital-transformation https://www.isaca.org/resources/isaca-journal/issues/

asked 01/10/2024
tho nguyen
32 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first