During an emergency response to a critical zero-day remote code execution vulnerability on an enterprise edge gateway, an administrator bypassed standard Change Advisory Board (CAB) review and applied an emergency patch directly to production systems. Within minutes of application, critical external API endpoints began returning persistent HTTP 500 errors, causing high-priority business service outages. To handle this ongoing operational disruption while adhering to formal change management frameworks, which of the following actions should the security operations team take FIRST?
- Execute the pre-approved emergency rollback plan to restore the last known stable configuration while recording the security impact.Cevap
- BReclassify the emergency software patch as a detective administrative control to bypass post-implementation verification requirements.
- CDisable all network firewall rule sets on the edge gateway to mitigate the software vulnerability flaws causing API service failure.
- DTrigger an automated orchestration playbook to isolate all internal application servers from the network infrastructure upon receiving service error alerts.
Cevap
Execute the pre-approved emergency rollback plan to restore the last known stable configuration while recording the security impact.
The primary objective of change management during a failed emergency deployment is to rapidly minimize business disruption while maintaining security integrity. Executing a documented, pre-approved rollback plan restores the system to a known good baseline state and ensures the security impact is recorded for subsequent review by the Change Advisory Board (CAB).
Adım Adım Çözüm
Anahtar Kavram
Emergency Change Control and Rollback Execution