ISC2 Certified Secure Software Lifecycle Professional (CSSLP) Practice Question
A development team wants to deploy a minor feature update during this week's release window. To embed security in the organization's change-management process and prevent new vulnerabilities, which action must be completed before the Change Advisory Board (CAB) can authorize the change for implementation?
Execute the rollback plan to restore the previous version if problems arise in production.
Conduct a formal security impact assessment as part of the CAB's pre-implementation review and obtain security sign-off.
Carry out a post-deployment root-cause analysis of incidents related to earlier releases.
Update the configuration management database and asset inventory to reflect the new version after deployment.
A security impact assessment (also called a security impact analysis) is an essential part of the change-approval workflow. It systematically identifies how the proposed modification could affect existing security controls, data integrity, compliance obligations, and overall risk. Performing this assessment during the CAB's pre-implementation review lets decision-makers require additional safeguards or reject the request if risk is unacceptable. Executing a rollback, performing a post-deployment root-cause analysis, and updating the configuration management database all occur after a change is approved and implemented; they do not help the CAB determine whether the change should proceed.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is a Change Advisory Board (CAB)?
Open an interactive chat with Bash
What is a Security Impact Assessment (SIA)?
Open an interactive chat with Bash
Why is pre-implementation review critical for security?
Open an interactive chat with Bash
What is a Change Advisory Board (CAB)?
Open an interactive chat with Bash
What is a Security Impact Assessment?
Open an interactive chat with Bash
How does the CAB’s pre-implementation review prevent vulnerabilities?
Open an interactive chat with Bash
ISC2 Certified Secure Software Lifecycle Professional (CSSLP)
Secure Software Lifecycle Management
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .