CISM Certified Information Security Manager – Question0732

Which of the following BEST ensures that security risks will be reevaluated when modifications in application developments are made?

A.
A problem management process
B. Background screening
C. A change control process
D. Business impact analysis (BIA)

Correct Answer: C

Explanation:

Explanation:
A change control process is the methodology that ensures that anything that could be impacted by a development change will be reevaluated. Problem management is the general process intended to manage all problems, not those specifically related to security. Background screening is the process to evaluate employee references when they are hired. BIA is the methodology used to evaluate risks in the business continuity process.