ISC2 Certified in Cybersecurity (CC)Security OperationsMedium

A software development team is adopting a DevOps methodology and needs to ensure that all changes to code, configurations, and infrastructure are tracked, approved, and auditable. This is crucial for maintaining system stability and security. Which security operations activity directly addresses this requirement?

  1. AChange management
  2. BAsset management
  3. CConfiguration management
  4. DPatch management
Show answer & explanation

Correct answer: A. Change management

Change management is the formal process for controlling all proposed changes to systems, services, or configurations, ensuring they are documented, assessed, approved, and tracked to minimize negative impact and maintain security.

Why the other options are wrong

  • B. Asset management tracks inventory, but not the process of changes to those assets.
  • C. Configuration management focuses on maintaining the desired state of systems and configurations, which is a component of change management, but doesn't encompass the entire approval and tracking process for all changes.
  • D. Patch management specifically deals with applying software updates and fixes, a type of change, but not the overall process for all changes.

Change Management

A formal process for controlling all proposed changes to systems, services, or configurations, ensuring they are documented, assessed, approved, and tracked.

  • Minimizes risks associated with changes.
  • Ensures traceability and accountability.
  • Critical for system stability and security.

Memory trick: Don't change it, manage it!

More Security Operations questions