Soru

Zorluk: OrtaChange Management and Security Impacts

An IT infrastructure team plans to implement a centralized Privileged Access Management (PAM) solution to manage administrative access across corporate servers. To comply with formal change management policies and minimize operational and security risks, in which sequence should the team perform the following change control steps?

  1. 1Document the change request including risk assessment, security impacts, and a comprehensive rollback plan.
  2. 2Submit the change proposal to the Change Advisory Board (CAB) for review and formal approval.
  3. 3Deploy and test the solution in a staging environment to validate functionality and practice rollback procedures.
  4. 4Implement the configuration in production during an approved maintenance window and verify system integrity.

Cevap

The correct sequence begins with documenting the change request and rollback plan, followed by obtaining CAB approval, testing in a staging environment, and finally deploying to production during an approved maintenance window.
A standard change management lifecycle follows a strict sequence: initial creation and risk/rollback documentation, formal evaluation and authorization by the Change Advisory Board (CAB), non-production staging validation to test functionality and rollback procedures, and finally, scheduled production implementation with post-change verification.

Adım Adım Çözüm

1
Document change details, risk assessment, impact analysis, and rollback plan.
A completed formal change request is established.
Risk and operational dependencies must be fully understood and documented prior to evaluation.
2
Submit the documentation to the Change Advisory Board (CAB) for authorization.
Formal CAB approval is granted.
Governance policy requires authorized sign-off before changes can be tested or scheduled.
3
Execute the change within a dedicated staging environment.
Successful functional testing and validation of the rollback procedure in staging.
Testing mitigates the risk of unexpected outages and validates the backout plan safely.
4
Deploy to the production environment during an approved maintenance window.
The PAM system is successfully deployed in production with post-change verification.
Executing during authorized maintenance minimizes user impact and fulfills change control requirements.

Anahtar Kavram

Standard Change Control Workflow Lifecycle
Bu soruyu puanla