ISC2 CISSP (Certified Information Systems Security Professional)Security OperationsMedium
A new change management process has been implemented at a software development company. A developer submits a request to deploy a critical security patch to a production web server. According to best practices for change management, which of the following is the MOST crucial step that MUST occur before the patch is applied to the production environment?
- APerform a full system backup of the production server.
- BUpdate the server's configuration management database (CMDB).
- CNotify end-users of potential service interruption.
- DObtain formal approval from the Change Advisory Board (CAB).
Show answer & explanationAnswer & explanation
Correct answer: D. Obtain formal approval from the Change Advisory Board (CAB).
Formal approval from the Change Advisory Board (CAB) is a crucial step in change management. The CAB reviews the proposed change, its potential impact, and ensures all necessary assessments (risk, testing, rollback) have been completed before authorizing deployment to production, preventing unauthorized or risky changes.
Why the other options are wrong
- A. Performing a full system backup is a critical step before implementation, but it's part of the implementation plan and follows approval, rather than being the *most crucial* step *before* application approval.
- B. Updating the CMDB is important for documentation, but it's often done after approval or deployment, not a prerequisite for approval.
- C. Notifying end-users is a good practice for communication, but it's typically done after a change is approved and scheduled, not a prerequisite for approval.
Change Advisory Board (CAB)
The CAB is a group of stakeholders, including IT, security, and business representatives, responsible for reviewing, approving, and prioritizing proposed changes to IT services and infrastructure. Its role is to minimize risk and ensure changes align with business objectives.
- Reviews and approves proposed changes.
- Assesses risks and impacts of changes.
- Ensures changes adhere to organizational policies.
Memory trick: Plan, Request, Assess, Approve, Implement, Review.