ISC2 Certified in Cybersecurity (CC)Security OperationsMedium
A company has identified a critical vulnerability in its widely used web server software. A patch has been released by the vendor. Before deploying the patch to production, the IT team tests it in a staging environment to ensure it does not introduce new issues or break existing functionalities. This process is a key step within which security operation activity?
- APatch management
- BChange management
- CAsset management
- DConfiguration management
Show answer & explanationAnswer & explanation
Correct answer: A. Patch management
The scenario describes the identification of a vulnerability, the availability of a vendor patch, and the testing and deployment of that patch, which are all integral steps of a patch management program.
Why the other options are wrong
- B. Change management is the overarching process for controlling *all* changes, but patch management is a specific type of change.
- C. Asset management tracks assets, not the process of updating software.
- D. Configuration management focuses on maintaining consistent system settings, not specifically applying updates.
Patch Management
The systematic process of identifying, acquiring, testing, and applying software updates (patches) to systems and applications to fix vulnerabilities, improve performance, or add features.
- Crucial for vulnerability remediation
- Involves testing before deployment
- Often automated but requires oversight
Memory trick: Maintaining systems keeps them secure and stable.