What is a significant issue related to application whitelisting after periodic updates?

Prepare for the NERC CIP Exam with comprehensive tools and resources! Study with flashcards and multiple choice questions, each explained in detail. Ace your certification with confidence now!

Application whitelisting is a security practice where only approved applications are allowed to run on a system. After periodic updates, a significant issue arises in that the whitelisting framework must be adjusted to accommodate any new software, updates to existing applications, or changes in the applications being used.

When updates occur, previously known-good systems may have applications modified or new applications installed, which might not be included in the existing whitelist. This necessitates significant adjustments to the whitelist to ensure the updated applications or newly installed software are recognized and permitted to execute. This process can be complex and time-consuming, often requiring extensive validation and testing to confirm that the whitelisted applications function correctly and do not introduce vulnerabilities.

This need for continual adjustment and validation is the crux of the problem highlighted, as it may lead to operational challenges and increased workload for IT and security teams managing the application whitelisting policies.

Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy