312-50V11 · Question #184
A bank stores and processes sensitive privacy information related to home loans. However, auditing has never been enabled on the system. What is the first step that the bank should take before…
The correct answer is B. Determine the impact of enabling the audit feature. Before enabling any new security control, an organization must first assess its operational and technical impact. Understanding the impact ensures that implementation does not disrupt existing systems or processes.
Question
A bank stores and processes sensitive privacy information related to home loans. However, auditing has never been enabled on the system. What is the first step that the bank should take before enabling the audit feature?
Options
- APerform a vulnerability scan of the system.
- BDetermine the impact of enabling the audit feature.
- CPerform a cost/benefit analysis of the audit feature.
- DAllocate funds for staffing of audit log review.
How the community answered
(55 responses)- A13% (7)
- B78% (43)
- C2% (1)
- D7% (4)
Why each option
Before enabling any new security control, an organization must first assess its operational and technical impact. Understanding the impact ensures that implementation does not disrupt existing systems or processes.
A vulnerability scan assesses system weaknesses and is unrelated to the process of safely enabling the audit feature itself.
Determining the impact of enabling auditing is the mandatory first step because it identifies how the feature will affect system performance, storage capacity, and operations before any commitment is made. Without this impact assessment, the bank risks degrading system availability or generating unmanageable log volumes, especially on a sensitive financial system that has never had auditing enabled.
A cost/benefit analysis is a valid step, but it can only be performed accurately after the impact is already understood - making it second, not first.
Allocating staffing funds is a planning activity that follows both the impact assessment and the decision to proceed, not a prerequisite first step.
Concept tested: Security audit enablement impact assessment
Source: https://csrc.nist.gov/publications/detail/sp/800-92/final
Topics
Community Discussion
No community discussion yet for this question.