nerdexam
CompTIA

CAS-002 · Question #151

A security administrator wants to verify and improve the security of a business process which is tied to proven company workflow. The security administrator was able to improve security by applying…

The correct answer is B. Conduct a gap analysis and recommend appropriate non-technical mitigating controls, and. When all available technical controls defined in the current security standard have been applied, the next appropriate step is a gap analysis - a structured comparison between the current security state and the desired state. This surfaces residual risks not addressed by…

Enterprise Security

Question

A security administrator wants to verify and improve the security of a business process which is tied to proven company workflow. The security administrator was able to improve security by applying controls that were defined by the newly released company security standard. Such controls included code improvement, transport encryption, and interface restrictions. Which of the following can the security administrator do to further increase security after having exhausted all the technical controls dictated by the company's security standard?

Options

  • AModify the company standard to account for higher security and meet with upper
  • BConduct a gap analysis and recommend appropriate non-technical mitigating controls, and
  • CConduct a risk analysis on all current controls, and recommend appropriate mechanisms to
  • DModify the company policy to account for higher security, adapt the standard accordingly,

How the community answered

(37 responses)
  • A
    14% (5)
  • B
    78% (29)
  • C
    5% (2)
  • D
    3% (1)

Explanation

When all available technical controls defined in the current security standard have been applied, the next appropriate step is a gap analysis - a structured comparison between the current security state and the desired state. This surfaces residual risks not addressed by technical controls alone. Non-technical (administrative, procedural, or compensating) controls such as policy enforcement, training, and process changes can then be recommended to close those gaps. Modifying the standard (Options A and D) requires organizational approval and is a longer-term governance action, not an immediate next step. Option C (risk analysis on current controls) is useful but does not directly lead to non-technical mitigations.

Topics

#gap analysis#non-technical controls#security standards#residual risk

Community Discussion

No community discussion yet for this question.

Full CAS-002 Practice