What aspect of vulnerability management reporting is primarily concerned with maintaining a record of all approved and implemented changes to an organization's IT infrastructure?
Configuration management is the correct answer because it involves the process of systematically handling changes to a system in such a way that the system maintains integrity over time, including the documentation and tracking of all the changes made. It ensures that if vulnerabilities are found, they can be traced back to specific changes, facilitating easier mitigation. Patching is a response to the identification of vulnerabilities and not a record-keeping process; compensating controls are security measures taken to offset the risk of an existing vulnerability but do not involve change documentation; and awareness, education, and training relate to the human factor and do not specifically track changes to IT infrastructure.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is Configuration Management in the context of IT?
Open an interactive chat with Bash
How does Configuration Management aid in vulnerability management?
Open an interactive chat with Bash
What are the other processes involved in vulnerability management?