CISSP - Security Operations - Section 7.15

Address personnel safety and security concerns including travel, security training and awareness, emergency management, and duress.

Describe personnel safety and security requirements covering travel security procedures, security awareness training, emergency management protocols, and duress response mechanisms. Recognise the organisational obligation to protect personnel from physical threats and explain how duress signals integrate with incident response procedures.

personnel safetyduressemergency managementtravel security

Practice question for this objective

Free sampleSecurity Operationsmedium

A regional bank's vulnerability scanner reports a critical authentication-bypass flaw in the internet-facing customer portal. The vendor has released an emergency patch this morning, but the change advisory board does not meet for four days. What should the security manager do FIRST?

  • ADeploy the patch immediately to the production portal without further review because the vendor has rated it critical.
  • BWait for the scheduled change advisory board so the patch can be reviewed alongside the routine monthly release.
  • CInvoke the documented emergency change procedure to expedite review and deployment within the maintenance window allowance. Correct
  • DDisable the customer portal entirely until the next change advisory board can authorise the patch deployment.
Recognise that emergency change procedures, not ad hoc deployment or routine queues, are the correct response to critical internet-facing vulnerabilities. Patch and vulnerability management programmes operate within change management, which provides an emergency path for critical exposures. The emergency procedure preserves authorisation, testing, and rollback discipline while compressing timelines so risk is reduced quickly without abandoning governance or causing unnecessary outage.

Why A is wrong: Skipping change control is tempting given the severity, but unreviewed production changes risk outages and violate governance; the correct route is the emergency change procedure, not no procedure.

Why B is wrong: Routine scheduling is appropriate for low-risk fixes, but a four-day delay on a critical internet-facing authentication bypass accepts unacceptable residual risk during the wait.

Why C is correct: Mature patch and vulnerability management programmes include an emergency change path precisely for critical, internet-facing risks; using it preserves governance while addressing the exposure quickly.

Why D is wrong: Taking the service offline addresses the vulnerability but creates a self-inflicted availability incident; compensating controls or expedited patching are proportionate alternatives.

See more CISSP practice questions, answers explained.

More in this domain

Back to all Security Operations objectives, or the CISSP cert hub.

Examworthy is not affiliated with or endorsed by (ISC)2. Original, blueprint-aligned practice material only.