Study. uk . com
  1. Home
  2. All questions
  3. Question 389

CISM study material · question 389 of 1000

A team deploys vendor patches straight to production on the vendor's assurance that they are safe. Which NIST expectation does this skip?

  1. Vendor patches are applied only to internet-facing systems, since those are the ones directly exposed to attack
  2. Vendor patches are approved by the vendor's own support desk before the change board is willing to schedule them
  3. Vendor patches are applied only during a change freeze
  4. Vendor patches are tested for their impact on security and on system settings before deployment
Show the answer

Answer: D. Vendor patches are tested for their impact on security and on system settings before deployment

SP 800-100 places patch testing inside configuration management: what a patch does to security and to system settings is established before it reaches production, whatever the vendor says.

Source: NIST SP 800-100 (NIST) — Table 2-1 Configuration Management

Challenge yourself on this topic → Study as cards