mediumMultiple Choice
ISC2 CC Practice Question: A security policy requires that all changes to a…
A security policy requires that all changes to a production system go through a formal change management process with approval from a change control board. This is an example of which security principle?
⚠ Common exam trap
Many candidates confuse governance (oversight/approval processes) with separation of duties (splitting a single task among people) — both involve multiple people, but only governance describes a formal policy and approval body.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Governance
Governance is the set of processes, policies, and controls that direct and oversee how an organization manages its systems and risks. A formal change management process with a change control board (CCB) that reviews and approves production changes is a textbook example of governance — it establishes oversight, accountability, and decision-making authority. The policy itself is the governance artifact, and the CCB is the governing body enforcing it.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Least privilege
Why it's wrong here
Least privilege restricts each account to the minimum access needed for its role; the stem describes mandatory approval of production changes, which is change control, not permission scoping. It tempts because both limit what users can do, yet least privilege concerns granted rights, not who authorises modifications.
- ✓
Governance
Why this is correct
A mandated change control board with formal approval is an oversight and decision-rights mechanism, which is governance. It directs and controls the organisation through defined authority, policies and accountability rather than implementing a technical safeguard, so it maps to the governance principle.
- ✗
Defense in depth
Why it's wrong here
Defense in depth layers multiple independent controls so one failure does not expose the system; the stem describes a single approval gate for production changes, which is change control. It tempts because formal processes feel like one layer among many, but no additional overlapping controls are described.
- ✗
Separation of duties
Why it's wrong here
Separation of duties splits a single task across different people so no one both requests and approves it; here the requirement is simply that a board authorises production changes, which is change control, not task-splitting. It tempts because approval by others resembles dual control, but the stem describes no divided duties.
Go deeper
Related to this question
Learn chapter
Risk Management and Security Controls
Key term
Organization
An Organization is a top-level container in Google Cloud that represents your company or entities and serves as the root node for all your cloud resources, policies, and access control.
Key term
Security policy
A security policy is a formal set of rules and guidelines that an organization establishes to protect its information assets and technology resources.
About these practice questions
This CC question is part of Courseiva's 989-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.