medium
Single Answer
0

Marek’s organization has a system that needs to receive a deviation from a defined security process. What best practice should he follow to ensure that this is done correctly?

Answer Options

A

He should conduct a risk assessment and document the results.

B

He should remove the system from the network segment to protect it.

C

He should ensure the deviation is approved through change management processes.

D

All of the above.

Correct Answer: C

Explanation

Marek should follow his organization’s change management process to document the change required and to ensure that it is regularly reviewed. This may not require a risk assessment since it may be a simple requirement or may have already been assessed. The type of security variance needed is not described, so it is not clear if removing the system from the network is necessary.