ISC2 Governance, Risk and Compliance (CGRC) Practice Question
You learn that developers plan to enable a new API endpoint on a production e-commerce system next week, which will require opening additional inbound firewall rules. To comply with the organization's system change-management process, what should the security team do first?
Schedule a post-implementation security assessment to confirm the new endpoint's controls are effective.
Apply the firewall changes during the next scheduled production maintenance window to minimize downtime.
Update the system security plan and asset inventory immediately after the change is implemented.
Submit a formal change request to the Change Control Board describing the security and operational impact.
A fundamental principle of change management is that no modification to an operational system is made until it has been formally proposed, documented, reviewed for risk and compliance impacts, and approved by an authorized body such as a Change Control Board (CCB). Submitting a detailed change request to the CCB triggers that evaluation and authorization workflow. Implementing the change, updating documentation, or conducting a post-implementation review are all important tasks, but they occur only after the change has been formally approved. Proceeding without prior approval would violate established policy and could introduce unmanaged risk to the production environment.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is the Change Control Board (CCB) and its role in the change-management process?
Open an interactive chat with Bash
Why is a formal change request important in the change-management process?
Open an interactive chat with Bash
What risks could arise from bypassing the change-management process?
Open an interactive chat with Bash
ISC2 Governance, Risk and Compliance (CGRC)
Compliance Maintenance
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .