ISC2 Governance, Risk and Compliance (CGRC) Practice Question
During a quarterly maintenance planning meeting, your organization proposes upgrading the production database servers from Linux 7 to Linux 9 to address end-of-life concerns. Before the Change Control Board can vote, what is the most appropriate first step the security control assessor should perform to evaluate potential risk and compliance impacts?
Install Linux 9 in a development environment and begin functional testing of applications.
Conduct a security impact analysis that compares the proposed upgrade to the current approved security and privacy baselines.
Coordinate with operations to schedule the production change window and notify affected users.
Update the system security plan (SSP) to reflect the new operating system version.
The change management process requires an initial security impact analysis comparing the proposed modification with the system's current, approved security and privacy baselines. This analysis identifies how the new operating system could affect confidentiality, integrity, availability, and compliance obligations, enabling decision-makers to judge risk before authorizing further activity. Updating the system security plan, scheduling deployment, or moving code into a development environment are all necessary tasks, but they come after the impact of the change has been formally assessed and the change has been approved. Starting testing or planning rollout without first completing the impact analysis would bypass a critical control and could expose the organization to unmanaged risk.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is a security impact analysis?
Open an interactive chat with Bash
What is a security and privacy baseline?
Open an interactive chat with Bash
Where does the Change Control Board fit into the process?
Open an interactive chat with Bash
ISC2 Governance, Risk and Compliance (CGRC)
Compliance Maintenance
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .