Study. uk . com
  1. Home
  2. All questions
  3. Question 567

CISM study material · question 567 of 1000

A change log records that each change occurred but says nothing about its effect. Which control requirement is unmet?

  1. Conducting security impact analyses to determine the effects of the changes
  2. Configuring the settings on each affected component to the most restrictive mode consistent with operation
  3. Maintaining the current baseline configuration for every component inside the authorisation boundary
  4. Restricting who is permitted to make changes to the components inside the authorisation boundary
Show the answer

Answer: A. Conducting security impact analyses to determine the effects of the changes

The monitoring configuration changes control requires the organisation to monitor changes to the information system and conduct security impact analyses to determine the effects of those changes.

Source: NIST SP 800-100 (NIST) — Table 14-1 CM Control Family

Challenge yourself on this topic → Study as cards