Question: To minimize security exposure introduced by changes to the IT environment, which of the following is MOST important to implement as part of change management?
To minimize security exposure introduced by changes to the IT environment, which of the following is MOST important to implement as part of change management?
A. Requiring approval by senior management B. Performing a business impact analysis (BIA) prior to implementation C. Performing post-change reviews before closing change tickets D. Conducting a security risk assessment prior to go-live
Correct Answer: B??? or D??????
_____________________
Note
The official answer is "B. Performing a business impact analysis (BIA) prior to implementation" (but it could also be wrong because it is not certified by ISACA) Other experts claim that the correct answer is: "D. Conducting a security risk assessment prior to go-live"
Your expert opinion (and explanation) is strongly requested. Many thanks in advance.
Many thanks!
Step by Step Solution
There are 3 Steps involved in it
Get step-by-step solutions from verified subject matter experts
