19. Which of the following prevents unauthorized modifications to internal processes, assets, and security controls?
Answer: A
Change management prevents unauthorized modifications to internal processes, assets, and security controls.
Change management is a systematic approach that ensures any changes to processes, assets, or security controls are made in a controlled and authorized manner, thereby preventing unauthorized modifications.
A) Change management
Change management is specifically designed to manage and oversee changes within an organization. It establishes procedures and protocols for proposing, reviewing, approving, and documenting changes, thereby minimizing the risk of unauthorized alterations that could compromise security and operational integrity.
B) Playbooks
Playbooks provide guidelines and procedures for responding to various scenarios, particularly in incident management. While they are useful for ensuring consistent responses, they do not directly prevent unauthorized modifications to internal processes or security controls.
C) Incident response
Incident response focuses on managing and mitigating security incidents after they occur. Although it may involve reviewing changes made during an incident, its primary purpose is not to prevent unauthorized modifications but rather to respond effectively to them.
D) Acceptable use policy
An acceptable use policy outlines the proper use of organizational resources and assets by employees. While it sets expectations for behavior, it does not actively manage or prevent unauthorized changes to internal processes or security controls.
Conclusion
Change management is essential in safeguarding an organization's processes and security controls by providing a structured approach to implementing changes. Other options, such as playbooks, incident response, and acceptable use policies, serve different purposes and do not directly address the prevention of unauthorized modifications. Thus, change management stands out as the definitive answer to the question.