Change Management Regulatory Frameworks & Compliance 2 — Questions and Answers
Question 1: Under Sarbanes-Oxley (SOX) Section 404, which change management control is most critical for IT systems that support financial reporting?
- Documenting all change requests in a ticketing system
- Segregation of duties between those who request and those who approve changes (Correct answer)
- Ensuring changes are deployed only during business hours
- Requiring vendor sign-off on all system modifications
Correct answer: Segregation of duties between those who request and those who approve changes
SOX Section 404 mandates segregation of duties so that no single individual can both initiate and approve changes to financially significant systems.
Question 2: Which U.S. federal regulation specifically governs change management practices in organizations that handle protected health information (PHI)?
- PCI DSS
- HIPAA Security Rule (Correct answer)
- FISMA
- GLBA Safeguards Rule
Correct answer: HIPAA Security Rule
The HIPAA Security Rule requires covered entities to implement policies and procedures for changes that affect ePHI systems, including formal change control processes.
Question 3: A financial services firm must comply with FFIEC guidelines. During a change freeze window, an emergency patch is needed to fix a critical vulnerability. What is the FIRST step?
- Deploy the patch immediately to minimize exposure
- Obtain emergency change approval per the defined exception process (Correct answer)
- Notify regulators before taking any action
- Postpone the patch until the freeze window ends
Correct answer: Obtain emergency change approval per the defined exception process
FFIEC guidelines require that even emergency changes follow an expedited but documented approval process rather than bypassing controls entirely.
Question 4: In the context of NERC CIP standards, which asset type triggers the most stringent change management requirements?
- Corporate HR systems
- Bulk Electric System cyber assets (Correct answer)
- Customer billing platforms
- Marketing automation tools
Correct answer: Bulk Electric System cyber assets
NERC CIP standards impose the strictest change management controls on Bulk Electric System (BES) cyber assets due to their critical infrastructure designation.
Question 5: A company subject to GDPR implements a new data processing system. Which change management consideration is MOST directly required by GDPR?
- Completing a Data Protection Impact Assessment (DPIA) before deployment (Correct answer)
- Filing the change with a national regulatory authority 30 days in advance
- Encrypting all data at rest using AES-256
- Obtaining ISO 27001 certification before go-live
Correct answer: Completing a Data Protection Impact Assessment (DPIA) before deployment
GDPR Article 35 requires a DPIA for high-risk processing activities before implementation, making it a direct change management gate.
Question 6: Which document type serves as the primary evidence that a change was conducted in compliance with regulatory requirements during an audit?
- Project charter
- Change advisory board meeting minutes (Correct answer)
- Risk register
- Business case
Correct answer: Change advisory board meeting minutes
CAB meeting minutes document who approved a change, the rationale, and any conditions imposed, providing auditors with the required evidence of controlled change governance.
Question 7: Under PCI DSS Requirement 6.4, what must organizations do before deploying changes to cardholder data environment systems?
- Submit changes to the PCI Security Standards Council for pre-approval
- Test changes in a separate environment and document impact before production deployment (Correct answer)
- Encrypt all code changes using asymmetric cryptography
- Require a minimum 72-hour review period for all changes
Correct answer: Test changes in a separate environment and document impact before production deployment
PCI DSS Requirement 6.4 mandates that changes be tested in a non-production environment and that impact on security controls be assessed before production deployment.
Under Sarbanes-Oxley (SOX) Section 404, which change management control is most critical for IT systems that support financial reporting?