- Home
- All questions
- Question 422
CISSP study material · question 422 of 500
A security lead argues patch testing is a security control. How does NIST SP 800-40 Rev. 4 characterise its purpose?
Show the answer
Answer: C. It reduces operational risk by finding problems the patch itself would cause before it reaches production.
SP 800-40 says testing a patch before deployment is intended to reduce operational risk by identifying problems with the patch before placing it into production.
Source: NIST SP 800-40 Rev. 4 (NIST) — SP 800-40 Rev. 4 > 2.3.1 Prepare to Deploy the Patch