An enterprise IT security team is implementing a major network security policy update to enforce microsegmentation across production database servers. Place the following change management steps in the correct chronological order from first to last to ensure proper security governance and operational continuity.
- 1Perform a security risk assessment and impact analysis for the proposed microsegmentation rules.
- 2Validate the microsegmentation rules and test backout procedures in a non-production staging environment.
- 3Submit the change request, staging test results, and rollback documentation to the Change Advisory Board (CAB) for review and authorization.
- 4Deploy the approved microsegmentation rules into the production environment during an authorized maintenance window.
- 5Conduct post-implementation verification, audit log review, and update the secure configuration baseline.
Cevap
The correct chronological sequence begins with performing a security risk assessment and impact analysis, followed by validating rules and rollback procedures in staging. Next, the change request and test evidence are submitted to the Change Advisory Board (CAB) for authorization. After approval, the change is implemented in production during a maintenance window. Finally, post-implementation verification and configuration baseline updates are completed.
A standard security-focused change management workflow follows a linear progression: initial security impact assessment, staging environment validation of the change and rollback plan, CAB review and approval, production execution within an authorized window, and post-implementation review with configuration baseline updating.
Adım Adım Çözüm
Anahtar Kavram
Change Control Lifecycle and Security Impact Assessment