Courseiva
mediumMultiple Choice

ISC2 CC Practice Question: A security policy requires that all changes to a…

A security policy requires that all changes to a production system go through a formal change management process with approval from a change control board. This is an example of which security principle?

⚠ Common exam trap

Many candidates confuse governance (oversight/approval processes) with separation of duties (splitting a single task among people) — both involve multiple people, but only governance describes a formal policy and approval body.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Governance

Governance is the set of processes, policies, and controls that direct and oversee how an organization manages its systems and risks. A formal change management process with a change control board (CCB) that reviews and approves production changes is a textbook example of governance — it establishes oversight, accountability, and decision-making authority. The policy itself is the governance artifact, and the CCB is the governing body enforcing it.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Least privilege

    Why it's wrong here

    Least privilege restricts each account to the minimum access needed for its role; the stem describes mandatory approval of production changes, which is change control, not permission scoping. It tempts because both limit what users can do, yet least privilege concerns granted rights, not who authorises modifications.

  • ✓

    Governance

    Why this is correct

    A mandated change control board with formal approval is an oversight and decision-rights mechanism, which is governance. It directs and controls the organisation through defined authority, policies and accountability rather than implementing a technical safeguard, so it maps to the governance principle.

  • ✗

    Defense in depth

    Why it's wrong here

    Defense in depth layers multiple independent controls so one failure does not expose the system; the stem describes a single approval gate for production changes, which is change control. It tempts because formal processes feel like one layer among many, but no additional overlapping controls are described.

  • ✗

    Separation of duties

    Why it's wrong here

    Separation of duties splits a single task across different people so no one both requests and approves it; here the requirement is simply that a board authorises production changes, which is change control, not task-splitting. It tempts because approval by others resembles dual control, but the stem describes no divided duties.

About these practice questions

This CC question is part of Courseiva's 989-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.