A regional bank's vulnerability scanner reports a critical authentication-bypass flaw in the internet-facing customer portal. The vendor has released an emergency patch this morning, but the change advisory board does not meet for four days. What should the security manager do FIRST?
- ADeploy the patch immediately to the production portal without further review because the vendor has rated it critical.
- BWait for the scheduled change advisory board so the patch can be reviewed alongside the routine monthly release.
- CInvoke the documented emergency change procedure to expedite review and deployment within the maintenance window allowance. Correct
- DDisable the customer portal entirely until the next change advisory board can authorise the patch deployment.
Why A is wrong: Skipping change control is tempting given the severity, but unreviewed production changes risk outages and violate governance; the correct route is the emergency change procedure, not no procedure.
Why B is wrong: Routine scheduling is appropriate for low-risk fixes, but a four-day delay on a critical internet-facing authentication bypass accepts unacceptable residual risk during the wait.
Why C is correct: Mature patch and vulnerability management programmes include an emergency change path precisely for critical, internet-facing risks; using it preserves governance while addressing the exposure quickly.
Why D is wrong: Taking the service offline addresses the vulnerability but creates a self-inflicted availability incident; compensating controls or expedited patching are proportionate alternatives.