nerdexam
CompTIA

CAS-001 · Question #505

A security policy states that all applications on the network must have a password length of eight characters. There are three legacy applications on the network that cannot meet this policy…

The correct answer is D. Provide a business justification for a risk exception. When legacy systems permanently cannot comply with a security policy, a formal risk exception with documented business justification is the required process, not risk inheritance or avoidance.

Enterprise Security

Question

A security policy states that all applications on the network must have a password length of eight characters. There are three legacy applications on the network that cannot meet this policy. Onesystem will be upgraded in six months, and two are not expected to be upgraded or removed from the network. Which of the following processes should be followed?

Options

  • AEstablish a risk matrix
  • BInherit the risk for six months
  • CProvide a business justification to avoid the risk
  • DProvide a business justification for a risk exception

How the community answered

(30 responses)
  • B
    7% (2)
  • C
    3% (1)
  • D
    90% (27)

Why each option

When legacy systems permanently cannot comply with a security policy, a formal risk exception with documented business justification is the required process, not risk inheritance or avoidance.

AEstablish a risk matrix

A risk matrix is an assessment tool used to score and prioritize risks by likelihood and impact, not a process for obtaining policy exception approval for non-compliant systems.

BInherit the risk for six months

Inheriting risk is the act of accepting risk transferred from a parent organization or external entity, not a mechanism for granting a time-limited policy exemption to internal non-compliant systems.

CProvide a business justification to avoid the risk

Risk avoidance means eliminating the source of the risk entirely by removing or replacing the asset, which is not possible for the two legacy applications that will not be upgraded or removed.

DProvide a business justification for a risk exceptionCorrect

A risk exception is the formal governance process for documenting a deliberate deviation from an established security policy when full compliance is not technically or operationally feasible. It requires a written business justification, management sign-off, and an auditable record that covers all non-compliant systems - including both the system pending upgrade and the two that will remain permanently non-compliant.

Concept tested: Formal risk exception process for policy non-compliance

Source: https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-30r1.pdf

Topics

#risk exception#legacy systems#policy compliance#risk management process

Community Discussion

No community discussion yet for this question.

Full CAS-001 Practice