CAS-001 · Question #505
A security policy states that all applications on the network must have a password length of eight characters. There are three legacy applications on the network that cannot meet this policy…
The correct answer is D. Provide a business justification for a risk exception. When legacy systems permanently cannot comply with a security policy, a formal risk exception with documented business justification is the required process, not risk inheritance or avoidance.
Question
A security policy states that all applications on the network must have a password length of eight characters. There are three legacy applications on the network that cannot meet this policy. Onesystem will be upgraded in six months, and two are not expected to be upgraded or removed from the network. Which of the following processes should be followed?
Options
- AEstablish a risk matrix
- BInherit the risk for six months
- CProvide a business justification to avoid the risk
- DProvide a business justification for a risk exception
How the community answered
(30 responses)- B7% (2)
- C3% (1)
- D90% (27)
Why each option
When legacy systems permanently cannot comply with a security policy, a formal risk exception with documented business justification is the required process, not risk inheritance or avoidance.
A risk matrix is an assessment tool used to score and prioritize risks by likelihood and impact, not a process for obtaining policy exception approval for non-compliant systems.
Inheriting risk is the act of accepting risk transferred from a parent organization or external entity, not a mechanism for granting a time-limited policy exemption to internal non-compliant systems.
Risk avoidance means eliminating the source of the risk entirely by removing or replacing the asset, which is not possible for the two legacy applications that will not be upgraded or removed.
A risk exception is the formal governance process for documenting a deliberate deviation from an established security policy when full compliance is not technically or operationally feasible. It requires a written business justification, management sign-off, and an auditable record that covers all non-compliant systems - including both the system pending upgrade and the two that will remain permanently non-compliant.
Concept tested: Formal risk exception process for policy non-compliance
Source: https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-30r1.pdf
Topics
Community Discussion
No community discussion yet for this question.