A change to open a database port from the Internet is headed to the city’s change advisory board without security review. Why should security participate in that CAB process?
Select an answer to reveal the explanation.
Short Explanation
CAB is where bad ideas get a seatbelt check. Security at the table spots “open that DB to the world” before it ships—not after the scanners scream.
Full Explanation
Change management governance should include security representation so proposed changes are evaluated for risk, misconfiguration, and control impact before approval. Reviewing only after production allows preventable exposures on municipal systems. Security’s role is risk-informed advice within the CAB, not automatic refusal of every change or a substitute for testing. Early participation reduces incident likelihood tied to operational changes.