Change Management Regulatory Frameworks & Compliance 4 — Questions and Answers
Question 1: A publicly traded company's change advisory board is reviewing a major ERP upgrade. Which SOX-related control must be confirmed before the change can be approved?
- The vendor has ISO 9001 certification
- User access rights will be reviewed and recertified post-deployment (Correct answer)
- The project manager has PMP certification
- The change was approved by the board of directors
Correct answer: User access rights will be reviewed and recertified post-deployment
SOX requires that access rights to financially significant systems be reviewed after major changes to ensure that inappropriate access was not introduced during implementation.
Question 2: Which compliance standard requires organizations to maintain a formal system development life cycle (SDLC) with integrated change control gates?
- CAN-SPAM Act
- NIST SP 800-128 (Correct answer)
- ADA Title III
- OSHA 1910.119
Correct answer: NIST SP 800-128
NIST SP 800-128 provides guidance for security-focused configuration change control integrated throughout the SDLC for federal information systems.
Question 3: When a change to a regulated system is rolled back due to failure, what compliance action is typically required?
- The rollback itself must be treated as a change and documented accordingly (Correct answer)
- Rollbacks are exempt from documentation requirements as they restore the previous state
- A new regulatory filing must be submitted within 24 hours
- The CAB must dissolve and reconvene with new members
Correct answer: The rollback itself must be treated as a change and documented accordingly
Regulators treat rollbacks as changes that must be documented, authorized, and logged because they alter the system state and could introduce their own risks.
Question 4: Under FISMA, federal agencies must implement change control processes aligned with which NIST publication?
- NIST SP 800-53 (Correct answer)
- NIST SP 800-12
- NIST SP 800-37
- NIST SP 800-61
Correct answer: NIST SP 800-53
NIST SP 800-53 provides the security and privacy controls, including CM (Configuration Management) controls, that FISMA-regulated federal agencies must implement.
Question 5: A compliance officer discovers that a software team deployed a change without CAB approval by classifying it as a 'standard change.' What is the MOST appropriate compliance response?
- Accept the change since standard changes are pre-approved
- Conduct a post-implementation review and determine if the change met standard change criteria (Correct answer)
- Immediately roll back the change regardless of its impact
- Report the developer to regulators for misconduct
Correct answer: Conduct a post-implementation review and determine if the change met standard change criteria
The correct response is to review whether the change legitimately qualified as a standard change and document findings, as misclassification of changes is a compliance risk.
Question 6: Which element must be included in a change record to satisfy most financial regulatory audit requirements?
- The developer's personal performance rating
- Business justification, approver identity, test results, and implementation date (Correct answer)
- The estimated market value of the changed system
- The number of users who will be affected by the change
Correct answer: Business justification, approver identity, test results, and implementation date
Auditors require evidence of why a change was made, who authorized it, how it was tested, and when it was implemented to demonstrate proper change governance.
Question 7: A multinational company must comply with both SOX and GDPR when deploying a new CRM system. Which approach best addresses both frameworks simultaneously?
- Apply the stricter of the two frameworks' requirements to all change activities
- Conduct separate compliance reviews for each regulation independently
- Integrate a unified change control process that maps controls to requirements from both frameworks (Correct answer)
- Prioritize SOX since it is a US law and the company is headquartered in the US
Correct answer: Integrate a unified change control process that maps controls to requirements from both frameworks
An integrated change control process that maps to multiple regulatory requirements is more efficient and reduces compliance gaps compared to running parallel siloed processes.
A publicly traded company's change advisory board is reviewing a major ERP upgrade.
Which SOX-related control must be confirmed before the change can be approved?