An organization is preparing to decommission a legacy Lightweight Directory Access Protocol (LDAP) directory server following a enterprise-wide migration to a cloud identity provider. To ensure business continuity and prevent unexpected service disruptions during the shutdown, which of the following actions should the security team perform FIRST to evaluate the security impact of this change?
- Perform a dependency analysis and review directory authentication logs to identify any remaining applications or devices reliant on the legacy service.Answer
- BDeploy network firewall access control lists to block port 389 traffic in production immediately to observe which systems fail.
- CReclassify the legacy LDAP server as a compensating control within the asset inventory to reduce risk rating prior to removal.
- DExecute automated orchestrations to purge all user accounts and directory schema attributes without Change Advisory Board review.
Answer
Perform a dependency analysis and review directory authentication logs to identify any remaining applications or devices reliant on the legacy service.
Prior to decommissioning core security or identity infrastructure, change management best practices require conducting a thorough dependency analysis and reviewing system logs. This proactive assessment identifies legacy applications, service accounts, or hardware devices still utilizing the service, allowing administrators to migrate them safely without causing unexpected outages.
Step-by-Step Solution
Key Concept
Dependency mapping and risk analysis in change management workflows