An enterprise security team plans to modify central authentication controls to enforce hardware-based multi-factor authentication across production subnets. To ensure operational continuity and minimize security risks, the team must follow the organization's formal change management process. Place the following change management steps in the correct chronological order from first to last.
- 1Draft and submit a formal change request detailing the scope, business justification, and security impact assessment.
- 2Present the change request to the Change Advisory Board (CAB) for operational review and formal authorization.
- 3Test the authentication policy updates in a staging environment and validate the rollback procedure.
- 4Deploy the change to the production environment within the approved maintenance window.
- 5Conduct post-implementation verification testing and update the Configuration Management Database (CMDB).
Answer
The correct sequence begins with submitting a formal change request and security impact assessment, obtaining Change Advisory Board approval, conducting staging tests and rollback verification, executing the change during an authorized maintenance window, and concluding with post-implementation verification and CMDB updating.
Standard change management follows a structured lifecycle to control risk: documentation and impact assessment, formal approval by the Change Advisory Board, non-production staging and backout plan testing, scheduled production execution, and post-implementation auditing with baseline configuration updates.
Step-by-Step Solution
Key Concept
Change Management Lifecycle and Security Control Implementation