QuestionQ1568

Technology and Security

An organization uses a centralized single sign-on (SSO) control that covers many applications. What is the BEST course of action when a new application is added to the environment after testing of the SSO control has been completed?

  • A Initiate a retest of the full control.
  • B Re-evaluate the control during the next assessment.
  • C Review the corresponding change control documentation.
  • D Retest the control using the new application as the only sample.
Explanation

A new application added to an environment using a centralized SSO control should be evaluated through the applicable change-control documentation. This provides evidence that the application’s integration with the established SSO control was authorized, assessed, tested, and implemented according to the organization’s change-management process, without unnecessarily repeating testing of the entire centralized control.

Community Discussion

No comments yet. Be the first to start the discussion!