Before a firewall cutover, the change board insists on an approval process and a named owner. Why are those steps security-relevant?
Select an answer to reveal the explanation.
Short Explanation
Change approval is the 'who signed off and who owns the mess if it breaks' sticker. Skipping it is how surprise holes appear in the firewall. It is not red tape theater — it is security hygiene.
Full Explanation
Change management processes include formal approval and clear ownership before security-impacting changes. Approval gates reduce ad-hoc modifications that introduce vulnerabilities, outages, or policy violations; ownership assigns accountability for execution and follow-through. Approval does not remove the need for impact analysis, backout planning, or testing. Treating change control as pure bureaucracy misses its role in protecting security posture.