<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Change Control Board in Exam Preparation</title>
    <link>https://community.isc2.org/t5/Exam-Preparation/Change-Control-Board/m-p/41621#M3388</link>
    <description>&lt;P&gt;I concur with the response. broadly speaking the role of the security team member on the CAB is two fold&lt;BR /&gt;1) determine the impact on security posture/risk and how it this change shall impact the improvement or reduction of security posture and thus impact the residual risk.&amp;nbsp;&lt;/P&gt;&lt;P&gt;case in point could be a change in administrative role definition has a potentially wider impact than say opening a specific port/protocol on the firewall in a restricted fashion&lt;/P&gt;&lt;P&gt;2) and based on the impact on deviation from baseline/increase in risk or any contravention to commonly accepted security principles (like NO any-any rule), the security personnel must approve/deny the change.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Often times the control owner MUST be informed of the risk of the change vs makign a approve/disapprove decision. those risk based change decisions can then be fed into the risk register&lt;/P&gt;</description>
    <pubDate>Sun, 13 Dec 2020 18:38:17 GMT</pubDate>
    <dc:creator>SecSri</dc:creator>
    <dc:date>2020-12-13T18:38:17Z</dc:date>
    <item>
      <title>Change Control Board</title>
      <link>https://community.isc2.org/t5/Exam-Preparation/Change-Control-Board/m-p/41612#M3386</link>
      <description>&lt;P&gt;Dear Team&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Appreciate your suggestions for below question.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="gmail-card-text"&gt;A security team member was selected as a member of a Change Control Board (CCB) for an organisation. Which of the following is one of their responsibilities?&lt;/P&gt;&lt;DIV class="gmail-question-choices-container"&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN class="gmail-multi-choice-letter"&gt;A.&amp;nbsp;&lt;/SPAN&gt;Approving or disapproving the change&lt;/LI&gt;&lt;LI&gt;&lt;SPAN class="gmail-multi-choice-letter"&gt;B.&amp;nbsp;&lt;/SPAN&gt;Determining the impact of the change&lt;/LI&gt;&lt;LI&gt;&lt;SPAN class="gmail-multi-choice-letter"&gt;C.&amp;nbsp;&lt;/SPAN&gt;Carrying out the requested change&lt;/LI&gt;&lt;LI&gt;&lt;SPAN class="gmail-multi-choice-letter"&gt;D.&amp;nbsp;&lt;/SPAN&gt;Logging the change&lt;/LI&gt;&lt;/UL&gt;&lt;/DIV&gt;&lt;DIV class="question-choices-container"&gt;&lt;P&gt;&lt;STRONG&gt;Option B&lt;/STRONG&gt; is the best choice here as the security member responsibility would be to&amp;nbsp;&lt;SPAN&gt;study &amp;amp; determine the impact of the proposed changes.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Option A is good choice here as members of CCB need to make the decision by approving or rejecting the change based on the information available.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any thoughts here?&lt;/P&gt;&lt;P&gt;Appreciate your inputs.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Nitesh&lt;/P&gt;&lt;/DIV&gt;</description>
      <pubDate>Sat, 12 Dec 2020 21:48:32 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Exam-Preparation/Change-Control-Board/m-p/41612#M3386</guid>
      <dc:creator>Nitesh</dc:creator>
      <dc:date>2020-12-12T21:48:32Z</dc:date>
    </item>
    <item>
      <title>Re: Change Control Board</title>
      <link>https://community.isc2.org/t5/Exam-Preparation/Change-Control-Board/m-p/41614#M3387</link>
      <description>&lt;P&gt;My thoughts on this one.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The question has at least &lt;STRONG&gt;two&lt;/STRONG&gt; correct answers.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="gmail-card-text"&gt;&lt;EM&gt;A security team member was selected as a member of a Change Control Board (CCB) for an organisation. Which of the following is one of their responsibilities?&lt;/EM&gt;&lt;/P&gt;&lt;DIV class="gmail-question-choices-container"&gt;&lt;UL&gt;&lt;LI&gt;&lt;EM&gt;&lt;SPAN class="gmail-multi-choice-letter"&gt;A.&amp;nbsp;&lt;/SPAN&gt;Approving or disapproving the change&lt;/EM&gt;&lt;/LI&gt;&lt;LI&gt;&lt;EM&gt;&lt;SPAN class="gmail-multi-choice-letter"&gt;B.&amp;nbsp;&lt;/SPAN&gt;Determining the impact of the change&lt;/EM&gt;&lt;/LI&gt;&lt;LI&gt;&lt;EM&gt;&lt;SPAN class="gmail-multi-choice-letter"&gt;C.&amp;nbsp;&lt;/SPAN&gt;Carrying out the requested change&lt;/EM&gt;&lt;/LI&gt;&lt;LI&gt;&lt;EM&gt;&lt;SPAN class="gmail-multi-choice-letter"&gt;D.&amp;nbsp;&lt;/SPAN&gt;Logging the change&lt;/EM&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;As part of the process, all team members should/must determine the impact of the change and then either approve or deny the change. For definition:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://project-management-knowledge.com/definitions/c/change-control-board-ccb/" target="_blank"&gt;https://project-management-knowledge.com/definitions/c/change-control-board-ccb/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I personally like this definition of the ITIL process which shows the steps that should be taken:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.cherwell.com/it-service-management/library/essential-guides/essential-guide-to-itil-change-management/#thechangemanagementprocessflow" target="_blank"&gt;https://www.cherwell.com/it-service-management/library/essential-guides/essential-guide-to-itil-change-management/#thechangemanagementprocessflow&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Based on this information, I would answer A but would not argue that B is also correct.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The Security personnel must review the change to ensure that it meets the business requirements without damaging or interfering with security implementation but they will also be part of the decision making team.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In actuality C could also be correct........depends on the system being modified at the user's request (a change to a firewall, opening ports, changing remote access, a change to the AV system to include/exclude a directory, etc.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So I stand corrected, there are at least 3 correct answers.&lt;/P&gt;&lt;P&gt;My thoughts on an early Sunday morn.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Be safe, be kind&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;d&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;/DIV&gt;</description>
      <pubDate>Sun, 13 Dec 2020 08:19:20 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Exam-Preparation/Change-Control-Board/m-p/41614#M3387</guid>
      <dc:creator>dcontesti</dc:creator>
      <dc:date>2020-12-13T08:19:20Z</dc:date>
    </item>
    <item>
      <title>Re: Change Control Board</title>
      <link>https://community.isc2.org/t5/Exam-Preparation/Change-Control-Board/m-p/41621#M3388</link>
      <description>&lt;P&gt;I concur with the response. broadly speaking the role of the security team member on the CAB is two fold&lt;BR /&gt;1) determine the impact on security posture/risk and how it this change shall impact the improvement or reduction of security posture and thus impact the residual risk.&amp;nbsp;&lt;/P&gt;&lt;P&gt;case in point could be a change in administrative role definition has a potentially wider impact than say opening a specific port/protocol on the firewall in a restricted fashion&lt;/P&gt;&lt;P&gt;2) and based on the impact on deviation from baseline/increase in risk or any contravention to commonly accepted security principles (like NO any-any rule), the security personnel must approve/deny the change.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Often times the control owner MUST be informed of the risk of the change vs makign a approve/disapprove decision. those risk based change decisions can then be fed into the risk register&lt;/P&gt;</description>
      <pubDate>Sun, 13 Dec 2020 18:38:17 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Exam-Preparation/Change-Control-Board/m-p/41621#M3388</guid>
      <dc:creator>SecSri</dc:creator>
      <dc:date>2020-12-13T18:38:17Z</dc:date>
    </item>
    <item>
      <title>Re: Change Control Board</title>
      <link>https://community.isc2.org/t5/Exam-Preparation/Change-Control-Board/m-p/41634#M3391</link>
      <description>&lt;P&gt;A is the most appropriate response in that a CCB is responsible for approving or denying the request.&amp;nbsp; B) also is a good answer but it is actually part of the approve/deny request.&lt;/P&gt;</description>
      <pubDate>Mon, 14 Dec 2020 13:58:58 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Exam-Preparation/Change-Control-Board/m-p/41634#M3391</guid>
      <dc:creator>PuettK</dc:creator>
      <dc:date>2020-12-14T13:58:58Z</dc:date>
    </item>
    <item>
      <title>Re: Change Control Board</title>
      <link>https://community.isc2.org/t5/Exam-Preparation/Change-Control-Board/m-p/41645#M3393</link>
      <description>&lt;P&gt;Answer B is the RCA or root cause and effect analysis before a change is approved or disapproved. Otherwise, your CCB is nothing more than a rubber stamp and nothing more. B comes before A making A the most correct answer.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;- b/eads&lt;/P&gt;</description>
      <pubDate>Mon, 14 Dec 2020 16:21:42 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Exam-Preparation/Change-Control-Board/m-p/41645#M3393</guid>
      <dc:creator>Beads</dc:creator>
      <dc:date>2020-12-14T16:21:42Z</dc:date>
    </item>
    <item>
      <title>Re: Change Control Board</title>
      <link>https://community.isc2.org/t5/Exam-Preparation/Change-Control-Board/m-p/41715#M3396</link>
      <description>&lt;P&gt;I agree CCB role is to approve or reject the changes depending on the impact analysis but do you think a security team member will have authority to approve/reject changes.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I suppose and what we practise, a security team member will assist in analysis of the change as part of CCB and provide info to Security/Business Manager to take decisions.&lt;/P&gt;</description>
      <pubDate>Thu, 17 Dec 2020 03:35:33 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Exam-Preparation/Change-Control-Board/m-p/41715#M3396</guid>
      <dc:creator>Nitesh</dc:creator>
      <dc:date>2020-12-17T03:35:33Z</dc:date>
    </item>
    <item>
      <title>Re: Change Control Board</title>
      <link>https://community.isc2.org/t5/Exam-Preparation/Change-Control-Board/m-p/41716#M3397</link>
      <description>&lt;P&gt;Yes, I have seen it happen on my own team.&amp;nbsp; However, we try to avoid doing so&amp;nbsp;because it rapidly turns into a pissing contest and appeals to higher authorities.&amp;nbsp; Instead, our goal is that approval/conditional approval/denial be unanimous.&amp;nbsp;&amp;nbsp;We accomplish this by focus on recommending better alternatives, or asking questions that results in the presenter (or their management) realizing they should be implementing the change differently.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 17 Dec 2020 04:09:34 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Exam-Preparation/Change-Control-Board/m-p/41716#M3397</guid>
      <dc:creator>denbesten</dc:creator>
      <dc:date>2020-12-17T04:09:34Z</dc:date>
    </item>
  </channel>
</rss>

