Page 794 Sybex CISSP Study guide
As I was reading the literature tonight, I came across this paragraph that is far too familiar for some of us who already. Work in corporate. And are either a member of the CAB. Or have been called into cab. To prevent situations like these for those of us who have been on 12 hour bridges. This story rings very true. I'll let you read it first and then comment your own. War story. Mine was a change to a config inside of a. Hosted server. On a VM that. Required an update to the application. But nobody had documented the existing. Keys or the certificates that needed to be applied to the server. So once the system was upgraded, the existing IIS certificate. Was no longer valid. And needed to be reapplied. The vendor then pointed at me saying I should have known this, but then I pointed at them saying they should have had this as a checklist before upgrading the application, And then the service desk who couldn't access the portal that they needed to that this application was. Providing as a service. Was pointing at us. And networking. Until finally the administrator who owns the server and installed it in the first place came online at 2 in the morning to provide us the certificate that he had saved on his personal. Work machine. That nobody else knew about.. Let's just say business continuity was not. A priority, and. Shared responsibility was still. Being learned. But by golly, they had an amazing change control process because. This upgrade was not an approved. Update. Nor a standard change. And let's just say that a few heads rolled.