CAS-001 · Question #518
A business owner has raised concerns with the Chief Information Security Officer (CISO) because money has been spent on IT security infrastructure, but corporate assets are still found to be…
The correct answer is D. Security controls are generally never 100% effective and gaps should be explained to. No security control achieves 100% effectiveness in practice. A patch management product and SOE hardening initiative are sound controls, but factors such as systems that are offline during patch windows, exceptions, legacy systems, newly deployed machines, or tool coverage gaps…
Question
A business owner has raised concerns with the Chief Information Security Officer (CISO) because money has been spent on IT security infrastructure, but corporate assets are still found to be vulnerable. The business recently implemented a patch management product and SOE hardening initiative. A third party auditor reported findings against the business because some systems were missing patches. Which of the following statements BEST describes this situation?
Options
- AThe business owner is at fault because they are responsible for patching the systems and have
- BThe audit findings are invalid because remedial steps have already been applied to patch servers
- CThe CISO has not selected the correct controls and the audit findings should be assigned to them
- DSecurity controls are generally never 100% effective and gaps should be explained to
How the community answered
(18 responses)- A6% (1)
- B6% (1)
- C11% (2)
- D78% (14)
Explanation
No security control achieves 100% effectiveness in practice. A patch management product and SOE hardening initiative are sound controls, but factors such as systems that are offline during patch windows, exceptions, legacy systems, newly deployed machines, or tool coverage gaps mean some systems will inevitably be missed. The correct response is not to blame the business owner (A), dismiss the findings (B), or reassign blame to the CISO (C), but to acknowledge that residual risk is inherent in all security programs and to communicate this gap clearly to business stakeholders. The CISO's role is to explain the nature of residual risk, quantify the gap, and work toward improving coverage - not to guarantee perfection. This answer reflects mature security governance: controls reduce risk but rarely eliminate it entirely.
Topics
Community Discussion
No community discussion yet for this question.