ISC2 CISSP (Certified Information Systems Security Professional)Security OperationsHard
During a routine audit, it is discovered that a critical security patch for an operating system was approved for deployment three months ago but has not yet been installed on several production servers. The delay is attributed to a lack of communication between the security team and the operations team regarding downtime windows. Which area of security operations needs immediate improvement?
- AIncident Response Plan
- BSecurity Information and Event Management (SIEM)
- CChange Management Process
- DVulnerability Management Process
Show answer & explanationAnswer & explanation
Correct answer: C. Change Management Process
The core issue is the failure to deploy an approved patch due to communication breakdown regarding downtime. This indicates a flaw in the Change Management Process, which should define how changes (like patch deployments) are planned, communicated, approved, and executed, including coordination of resources and timing.
Why the other options are wrong
- A. Incident Response deals with reacting to security incidents, not proactively managing approved changes and deployments.
- B. SIEM is for logging and monitoring; it wouldn't directly solve the communication and coordination issue for deploying approved changes.
- D. Vulnerability Management identifies and prioritizes vulnerabilities; the patch was already identified and approved, so this process worked up to a point.
Change Management Process
The Change Management Process is a formal procedure for managing all changes to an organization's IT environment, ensuring that changes are introduced in a controlled, coordinated, and documented manner to minimize disruption and risk.
- Minimizes risks from changes.
- Includes planning, approval, implementation, and review.
- Crucial for maintaining system stability and security.
Memory trick: Changes need 'Control' to not break things.