CAS-001 · Question #167
A corporation has expanded for the first time by integrating several newly acquired businesses. Which of the following are the FIRST tasks that the security team should undertake? (Select TWO).
The correct answer is E. Develop interconnection policy. F. Conduct a risk analysis of each acquired company's networks. When integrating acquired businesses, the security team must first assess risk and establish governance before implementing any technical controls.
Question
A corporation has expanded for the first time by integrating several newly acquired businesses. Which of the following are the FIRST tasks that the security team should undertake? (Select TWO).
Options
- ARemove acquired companies Internet access.
- BFederate identity management systems.
- CInstall firewalls between the businesses.
- DRe-image all end user computers to a standard image.
- EDevelop interconnection policy.
- FConduct a risk analysis of each acquired company's networks.
How the community answered
(37 responses)- A14% (5)
- B3% (1)
- C8% (3)
- D3% (1)
- E73% (27)
Why each option
When integrating acquired businesses, the security team must first assess risk and establish governance before implementing any technical controls.
Removing Internet access is a disruptive operational action that should not be taken before understanding what risks actually exist through a proper risk analysis.
Federating identity management systems is a technical integration step that is premature until a risk analysis and interconnection policy define how and whether systems should be linked.
Installing firewalls is a technical control that should only be deployed after risk analysis and policy development determine the appropriate network segmentation requirements.
Re-imaging end user computers is an extreme and disruptive action that cannot be justified without first assessing the actual risk posture of each acquired company.
Developing an interconnection policy establishes the governance framework and rules of engagement for how the acquired companies' networks will interact with the parent organization, which must exist before any technical integration begins.
Conducting a risk analysis of each acquired company's networks provides the foundational understanding of existing vulnerabilities, compliance gaps, and threat exposure - without this, any technical actions taken could be misinformed or counterproductive.
Concept tested: Mergers and acquisitions security integration sequencing
Source: https://csrc.nist.gov/publications/detail/sp/800-47/rev-1/final
Topics
Community Discussion
No community discussion yet for this question.