CAS-001 · Question #356
A newly-appointed risk management director for the IT department at Company XYZ, a major pharmaceutical manufacturer, needs to conduct a risk analysis regarding a new system which the developers…
The correct answer is B. A definitive plan of action and milestones which lays out resolutions to all vulnerabilities within six months. A Plan of Action and Milestones (POA&M) is a formal risk management document that lists identified vulnerabilities, assigns ownership, sets remediation deadlines, and tracks progress. Before accepting residual risk and allowing a system with known vulnerabilities to go live…
Question
A newly-appointed risk management director for the IT department at Company XYZ, a major pharmaceutical manufacturer, needs to conduct a risk analysis regarding a new system which the developers plan to bring on-line in three weeks. The director begins by reviewing the thorough and well-written report from the independent contractor who performed a security assessment of the system. The report details what seem to be a manageable volume of infrequently exploited security vulnerabilities. The director decides to implement continuous monitoring and other security controls to mitigate the impact of the vulnerabilities. Which of the following should the director require from the developers before agreeing to deploy the system?
Options
- AAn incident response plan which guarantees response by tier two support within 15 minutes of an incident.
- BA definitive plan of action and milestones which lays out resolutions to all vulnerabilities within six months.
- CBusiness insurance to transfer all risk from the company shareholders to the insurance company.
- DA prudent plan of action which details how to decommission the system within 90 days of becoming
How the community answered
(59 responses)- A7% (4)
- B49% (29)
- C32% (19)
- D12% (7)
Explanation
A Plan of Action and Milestones (POA&M) is a formal risk management document that lists identified vulnerabilities, assigns ownership, sets remediation deadlines, and tracks progress. Before accepting residual risk and allowing a system with known vulnerabilities to go live, the risk director should require a written commitment from developers detailing exactly how and when each vulnerability will be resolved. This ensures risk is being actively managed, not ignored. Option A is unrealistic (15-minute tier-2 SLA guarantees are not feasible for all incidents). Option C (insurance) transfers financial risk but does not reduce technical risk or fix vulnerabilities. Option D (decommissioning plan) is defeatist and does not address remediation.
Topics
Community Discussion
No community discussion yet for this question.