A cybersecurity analyst is preparing a formal change request to deploy an updated security rule set across all enterprise Web Application Firewalls (WAF). To comply with standard change management procedures prior to submitting the proposal for Change Advisory Board (CAB) review, which TWO of the following elements must be documented and included in the request? (Select TWO.)
- A risk assessment detailing potential business impact and service disruption vulnerabilitiesAnswer
- A step-by-step rollback plan outlining exact procedures to restore the previous WAF configuration if issues ariseAnswer
- CAn execution override authorizing the bypass of sandbox environment testing to accelerate deployment
- DA directive to deploy updates immediately into production ahead of scheduled maintenance windows
Answer
The change request must include a risk assessment detailing potential business impact and a step-by-step rollback plan outlining exact procedures to restore the previous WAF configuration if issues arise.
Formal change management procedures require identifying potential operational risks through a risk assessment and establishing a documented rollback plan to safely revert systems if the change causes unforeseen service disruption.
Step-by-Step Solution
Key Concept
Change Management Documentation Requirements