CAS-002 · Question #136
A newly-appointed risk management director for the IT department at Company XYZ, a major pharmaceutical manufacturer, needs to conduct a risk analysis regarding a new system which the developers…
The correct answer is B. A definitive plan of action and milestones which lays out resolutions to all vulnerabilities. Before deploying a system with known vulnerabilities, the risk director must require a Plan of Action and Milestones (POA&M) that formally commits to resolving each identified vulnerability.
Question
A newly-appointed risk management director for the IT department at Company XYZ, a major pharmaceutical manufacturer, needs to conduct a risk analysis regarding a new system which the developers plan to bring on-line in three weeks. The director begins by reviewing the thorough and well-written report from the independent contractor who performed a security assessment of the system. The report details what seem to be a manageable volume of infrequently exploited security vulnerabilities. The director decides to implement continuous monitoring and other security controls to mitigate the impact of the vulnerabilities. Which of the following should the director require from the developers before agreeing to deploy the system?
Options
- AAn incident response plan which guarantees response by tier two support within 15 minutes
- BA definitive plan of action and milestones which lays out resolutions to all vulnerabilities
- CBusiness insurance to transfer all risk from the company shareholders to the insurance
- DA prudent plan of action which details how to decommission the system within 90 days of
How the community answered
(42 responses)- A7% (3)
- B57% (24)
- C24% (10)
- D12% (5)
Why each option
Before deploying a system with known vulnerabilities, the risk director must require a Plan of Action and Milestones (POA&M) that formally commits to resolving each identified vulnerability.
A rapid incident response time guarantee addresses reaction speed after a breach but does not reduce the attack surface created by unmitigated vulnerabilities before the system goes live.
A POA&M is the formal risk management document that records each identified vulnerability alongside the planned remediation action, responsible owner, and target completion date. Requiring a POA&M before deployment ensures all vulnerabilities are tracked with accountable resolution timelines, which is standard practice under frameworks such as NIST RMF and is necessary for authorizing operation of a system with residual risk.
Business insurance transfers financial risk to an insurer but does not mitigate the technical vulnerabilities or reduce the probability or impact of a successful exploit.
Planning to decommission the system within 90 days assumes failure rather than mitigating vulnerabilities - it is not an acceptable risk treatment for a system about to be deployed.
Concept tested: Plan of Action and Milestones for pre-deployment vulnerability management
Source: https://csrc.nist.gov/publications/detail/sp/800-37/rev-2/final
Topics
Community Discussion
No community discussion yet for this question.