CISM Certified Information Security Manager – Question0604

Which of the following would BEST enable an organization to effectively monitor the implementation of standardized configurations?

A.
Implement a separate change tracking system to record changes to configurations.
B. Perform periodic audits to detect non-compliant configurations.
C. Develop policies requiring use of the established benchmarks.
D. Implement automated scanning against the established benchmarks.

Correct Answer: D