An audit of an application reveals that the current configuration does not match the configuration of the originally implemented application. Which of the following is the FIRST action to be taken?
Correct Answer: B
Configuration is the process of setting up and maintaining the parameters, settings, and options of a system or application to ensure its optimal performance and security. Configuration change is the process of modifying or updating the configuration of a system or application to meet the changing needs or requirements of the organization and the stakeholders. Configuration change should be controlled and documented by using a change control process. A change control process is a process that defines the steps, roles, and responsibilities for requesting, approving, implementing, testing, and documenting the configuration changes of a system or application. A change control process can help to ensure that the configuration changes are authorized, validated, and traceable, and that they do not adversely affect the functionality, security, or availability of the system or application. The first action to be taken when an audit of an application reveals that the current configuration does not match the configuration of the originally implemented application is to verify the approval of the configuration change. Verifying the approval of the configuration change is the process of checking and confirming that the configuration change was requested, reviewed, and authorized by the appropriate parties, such as the change owner, the change manager, or the change board, before it was implemented. Verifying the approval of the configuration change can help to determine if the configuration change was legitimate, necessary, and compliant with the organization's policies and standards, as well as to identify and resolve any issues or discrepancies that may arise from the configuration change. Recommending an update to the change control process, rolling back the application to the original configuration, or documenting the changes to the configuration are not the first actions to be taken when an audit of an application reveals that the current configuration does not match the configuration of the originally implemented application, as they are more related to the improvement, restoration, or reporting aspects of the configuration change. References: CISSP All-in-One Exam Guide, Eighth Edition, Chapter 11: Security Operations, page 665; CISSP Official (ISC)2 Practice Tests, Third Edition, Domain 7: Security Operations, Question 7.9, page 273.