An assessor is reviewing whether an organization appropriately analyzed the security impact of a new release of an application. Which of the following documents is MOST useful for the assessor to review?
A.
A description of the change from the software vendor
B.
Change Control Board (CCB) meeting minutes and supporting documents
C.
System audit logs showing that the change occurred, when, and by whom
D.
A log of security incidents/issues after the change was implemented
Chosen Answer:
This is a voting comment (?). You can switch to a simple comment. It is better to Upvote an existing comment if you don't have anything to add.
Submit