CCSP Domain 5: Maintenance Flashcards
How often should CMB meet?
often enough to address organizational needs and reduce frustration with delay; frustrated employees and managers can increase risk to the organization by implementing their own, unapproved modifications to the environment
What should the update procedure include?
- document how, when and why the update was initiated by the vendor
- move the update through the CM process
What is the update procedure?
- put the systems and devices into maintenance mode
- apply the updates to the necessary systems and devices; annotate the asset inventory to reflect the changes
- verify the update; run tests on the production environment to ensure all necessary systems and devices have received the update - if missed, repeat the installation until complete
- validate the modifications; ensure intended results of the update have taken effect and interactions with the rest of the environment work appropriately
- return to normal operations
What document should cover patching?
patching, like any other form of maintenacne should be covered in SLAs
Agreed upon schedule and patching threshold should be covered by what document?
contract
What does configuration management entail?
documenting the approved settings for systems and software, which helps establish baselines within the organization
What is CM?
change and configuration management
What does CM begins with?
baselining
What is baselining?
a way of taking an accurante account of the desired standard state
What is important to incorporate in baselines?
security controls with a thorough description of each one’s purpose, dependencies and supporting rationale
Why is it essential to include security controls in baselines?
so that business is informed about risk management as changes are considered to be implemented through the CM process; need to know if changes introduce any new risks for which compensatory controls would need to be implemented
What stakeholders should provide input for creating baselines?
IT, security office, management, users
Baseline should be a reflection of what?
risk appetite of the organization; provides optimum balance between security and operational functionality
When baseline provides the gratest value?
when it’s applied to the greatest amount of covered systems
Are baselines the be-all and end-all of system security?
no, it just serves as a standard against which to compare and validate all systems in the organization