Question

Difficulty: MediumChange Management and Security Impacts

An enterprise security team plans to modify central authentication controls to enforce hardware-based multi-factor authentication across production subnets. To ensure operational continuity and minimize security risks, the team must follow the organization's formal change management process. Place the following change management steps in the correct chronological order from first to last.

  1. 1Draft and submit a formal change request detailing the scope, business justification, and security impact assessment.
  2. 2Present the change request to the Change Advisory Board (CAB) for operational review and formal authorization.
  3. 3Test the authentication policy updates in a staging environment and validate the rollback procedure.
  4. 4Deploy the change to the production environment within the approved maintenance window.
  5. 5Conduct post-implementation verification testing and update the Configuration Management Database (CMDB).

Answer

The correct sequence begins with submitting a formal change request and security impact assessment, obtaining Change Advisory Board approval, conducting staging tests and rollback verification, executing the change during an authorized maintenance window, and concluding with post-implementation verification and CMDB updating.
Standard change management follows a structured lifecycle to control risk: documentation and impact assessment, formal approval by the Change Advisory Board, non-production staging and backout plan testing, scheduled production execution, and post-implementation auditing with baseline configuration updates.

Step-by-Step Solution

1
Identify the initial phase of formal change governance.
The change request and security impact assessment are drafted and submitted first.
A formal proposal detailing the scope, potential security vulnerabilities, and affected systems is mandatory before governance bodies can evaluate the risk.
2
Determine the required governance review and approval stage.
The change request is submitted to the Change Advisory Board (CAB) for approval.
The CAB must evaluate organizational impact, resource availability, and scheduling conflicts prior to technical execution.
3
Determine the pre-implementation risk mitigation stage.
The policy change is validated in a staging environment and the rollback procedure is tested.
Testing in non-production validates functionality and ensures a safe fallback mechanism exists before modifying production systems.
4
Identify the production implementation step.
The deployment is executed during the scheduled maintenance window.
Implementing changes during designated low-impact windows minimizes disruption to live operational business services.
5
Identify the final closure and baseline updating phase.
Post-implementation security testing is conducted and the CMDB baseline is updated.
Verifying production stability ensures security requirements are met, while updating the CMDB records the new operational baseline for compliance and auditing.

Key Concept

Change Management Lifecycle and Security Control Implementation
Rate this question