ExamGecko
Question list
Search
Search

Question 637 - CISM discussion

Report
Export

A new application has entered the production environment with deficient technical security controls. Which of the following is MOST Likely the root cause?

A.
Inadequate incident response controls
Answers
A.
Inadequate incident response controls
B.
Lack of legal review
Answers
B.
Lack of legal review
C.
Inadequate change control
Answers
C.
Inadequate change control
D.
Lack of quality control
Answers
D.
Lack of quality control
Suggested answer: C

Explanation:

Change control is the process of ensuring that changes to an information system are authorized, tested, documented and implemented in a controlled manner. Inadequate change control can result in deficient technical security controls, such as missing patches, misconfigurations, vulnerabilities or errors in the new application.

Reference= CISM Review Manual, 27th Edition, Chapter 4, Section 4.3.2, page 2291

asked 01/10/2024
Nikhil George
34 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first