A healthcare organization's cloud operations team plans to update the TLS configuration on its primary API gateways by disabling TLS 1.0 and 1.1 to comply with updated security baselines. Before the Change Advisory Board (CAB) approves this modification, which action should the security team mandate to evaluate the potential security and functional impact of the proposed change?
- Perform an inventory and dependency analysis to identify internal and legacy external systems that rely on older encryption protocols.Answer
- BApply an emergency firewall exception that permits unencrypted HTTP fallback traffic during the maintenance window.
- CInitiate an automated rollback script immediately prior to submitting the formal change request to verify backout readiness.
- DReclassify the protocol deprecation as a standard emergency change to expedite deployment without pre-implementation review.
Answer
Perform an inventory and dependency analysis to identify internal and legacy external systems that rely on older encryption protocols.
Performing a thorough dependency analysis allows the security and operations teams to identify legacy applications, client software, or third-party services that depend on older TLS versions. Discovering these dependencies before the Change Advisory Board (CAB) approves the request ensures that potential outages are identified early, remediation plans are established, and security impacts are fully understood.
Step-by-Step Solution
Key Concept
Change Management Security Impact and Dependency Analysis