ISC2 Governance, Risk and Compliance (CGRC) Practice Question
During a planned upgrade to an online banking system, the development team identifies a new encryption module that will require additional firewall ports to be opened in production. According to an effective system change-management process, what is the most appropriate next step?
Document the change and submit it to the Change Control Board for risk and compliance review before any deployment.
Push the updated code to the test environment and only involve the Change Control Board if issues are discovered.
Immediately open the ports in the development and production firewalls to avoid delaying the project schedule.
Schedule a penetration test of the new module after it is live to satisfy audit requirements.
Sound change management requires that every proposed modification be formally recorded and routed for risk, security, and compliance evaluation before it is implemented. Creating and submitting a change record (often called a Request for Change) to the Change Control Board (or similar approval body) triggers that review. Acting first-such as opening ports, deploying code, or running tests in production-bypasses the mandated approval gate and can introduce unassessed risk. Likewise, postponing approval until after deployment or only if problems surface violates the principle of prior authorization. Therefore, documenting the change and seeking CCB approval is the correct initial action.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is a Change Control Board (CCB)?
Open an interactive chat with Bash
What is the importance of documenting changes before implementation?
Open an interactive chat with Bash
What is a Request for Change (RFC) in change management?
Open an interactive chat with Bash
ISC2 Governance, Risk and Compliance (CGRC)
Compliance Maintenance
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .