Question

Difficulty: HardChange Management and Security Impacts

An enterprise IT security team is implementing a major network security policy update to enforce microsegmentation across production database servers. Place the following change management steps in the correct chronological order from first to last to ensure proper security governance and operational continuity.

  1. 1Perform a security risk assessment and impact analysis for the proposed microsegmentation rules.
  2. 2Validate the microsegmentation rules and test backout procedures in a non-production staging environment.
  3. 3Submit the change request, staging test results, and rollback documentation to the Change Advisory Board (CAB) for review and authorization.
  4. 4Deploy the approved microsegmentation rules into the production environment during an authorized maintenance window.
  5. 5Conduct post-implementation verification, audit log review, and update the secure configuration baseline.

Answer

The correct chronological sequence begins with performing a security risk assessment and impact analysis, followed by validating rules and rollback procedures in staging. Next, the change request and test evidence are submitted to the Change Advisory Board (CAB) for authorization. After approval, the change is implemented in production during a maintenance window. Finally, post-implementation verification and configuration baseline updates are completed.
A standard security-focused change management workflow follows a linear progression: initial security impact assessment, staging environment validation of the change and rollback plan, CAB review and approval, production execution within an authorized window, and post-implementation review with configuration baseline updating.

Step-by-Step Solution

1
Identify potential security risks, technical dependencies, and business impacts.
Establishes baseline risk parameters and defines scope.
Security impact assessment must precede technical testing and formal review.
2
Execute technical testing and validate rollback steps in a staging environment.
Confirms the change works as designed without causing unintended outages.
Empirical testing in non-production is required to prove feasibility before seeking authorization.
3
Present the change package to the Change Advisory Board (CAB).
Obtains formal business and operational approval for deployment.
CAB approval ensures governance alignment and prevents scheduling conflicts.
4
Implement the configuration change during the scheduled maintenance window.
Applies the new security policies live in production.
Production execution must adhere to authorized timing constraints.
5
Perform post-implementation review (PIR) and update system baselines.
Confirms operational stability and updates security baseline records.
Ensures auditability and records the final post-change state.

Key Concept

Change Control Lifecycle and Security Impact Assessment
Rate this question