CAS-002 · Question #184
A new web application system was purchased from a vendor and configured by the internal development team. Before the web application system was moved into production, a vulnerability assessment was…
The correct answer is D. Team lead in a weekly report. A minor pre-production security configuration issue should be reported to the team lead through normal channels such as a weekly report, as it does not warrant immediate executive escalation.
Question
A new web application system was purchased from a vendor and configured by the internal development team. Before the web application system was moved into production, a vulnerability assessment was conducted. A review of the vulnerability assessment report indicated that the testing team discovered a minor security issue with the configuration of the web application. The security issue should be reported to:
Options
- ACISO immediately in an exception report.
- BUsers of the new web application system.
- CThe vendor who supplied the web application system.
- DTeam lead in a weekly report.
How the community answered
(37 responses)- A3% (1)
- B5% (2)
- C16% (6)
- D76% (28)
Why each option
A minor pre-production security configuration issue should be reported to the team lead through normal channels such as a weekly report, as it does not warrant immediate executive escalation.
Immediate CISO notification via an exception report is reserved for critical or high-severity security incidents, not minor configuration findings discovered in pre-production testing.
End users of the application should not be informed of security configuration details, as disclosure could expose the vulnerability to a wider audience before it is remediated.
The vulnerability resulted from the internal development team's configuration of the application, not a defect in the vendor-supplied software, so the vendor is not the appropriate party to notify.
Because the finding is classified as minor and was discovered before the system entered production, the risk is low and manageable through normal workflow. Routing it to the team lead in a weekly report follows proportional escalation procedures, allowing the development team to remediate it as part of their regular cadence without diverting executive attention unnecessarily.
Concept tested: Vulnerability reporting escalation proportional to severity
Source: https://csrc.nist.gov/publications/detail/sp/800-61/rev-2/final
Topics
Community Discussion
No community discussion yet for this question.