Question

Difficulty: MediumChange Management and Security Impacts

An enterprise security team needs to deploy an urgent software patch to core payment gateways to remediate an actively exploited remote code execution vulnerability. To balance immediate threat mitigation with enterprise governance and risk management requirements, which of the following actions should the team take FIRST according to formal change management principles?

  1. Submit an emergency change request to the Emergency Change Advisory Board for expedited authorization with a documented backout procedure.Answer
  2. B
    Deploy the software patch directly into the production environment immediately and log a retroactive change ticket after confirming system uptime.
  3. C
    Reclassify emergency zero-day patch deployments as pre-approved standard changes to eliminate formal authorization steps.
  4. D
    Defer the patch installation until the next scheduled monthly Change Advisory Board review meeting to conduct full non-production regression testing.

Answer

The team should submit an emergency change request to the Emergency Change Advisory Board (eCAB) for expedited authorization with a documented backout procedure.
Emergency Change Management procedures exist to handle urgent situations like zero-day vulnerability mitigation. Submitting an emergency change request to an Emergency Change Advisory Board allows for expedited evaluation of security impact and risk, while ensuring a backout plan is established to protect operational continuity.

Step-by-Step Solution

1
Evaluate the context of the change
Identified as a critical vulnerability requiring rapid mitigation without skipping governance
Emergency patches address active threats that cannot wait for standard change review cycles.
2
Select the correct change control path
Choose the Emergency Change Advisory Board (eCAB) process
The emergency change workflow provides expedited review and risk assessment designed specifically for urgent security fixes.
3
Ensure essential safety mechanisms are included
Attach a rollback/backout plan and conduct basic risk verification
Even under emergency conditions, a rollback plan prevents extended downtime if the patch causes unexpected failure.

Key Concept

Emergency Change Control and Security Impact Assessment
Rate this question