QuestionQ570

Information Security Governance

Proposed modifications to a large organization’s enterprise resource planning (ERP) system would breach existing security standards. What should be done FIRST to resolve this conflict?

  • A Perform a cost-benefit analysis
  • B Calculate business impact levels.
  • C Validate current standards.
  • D Implement updated standards.
Explanation

Existing security requirements must be validated before changes are accepted or standards are revised. This establishes the authoritative control baseline and confirms whether the proposed configuration is noncompliant under currently applicable security requirements. Security-control assessment and configuration-change processes require evaluating changes against established controls before final implementation.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!