CAS-002 · Question #199
The lead systems architect on a software development project developed a design which is optimized for a distributed computing environment. The security architect assigned to the project has…
The correct answer is C. Document mitigations to the security concerns and facilitate a meeting between the. When security risks are ignored due to communication failures, the network engineer should document mitigations formally and facilitate dialogue between the relevant architects.
Question
The lead systems architect on a software development project developed a design which is optimized for a distributed computing environment. The security architect assigned to the project has concerns about the integrity of the system, if it is deployed in a commercial cloud. Due to poor communication within the team, the security risks of the proposed design are not being given any attention. A network engineer on the project has a security background and is concerned about the overall success of the project. Which of the following is the BEST course of action for the network engineer to take?
Options
- AAddress the security concerns through the network design and security controls.
- BImplement mitigations to the security risks and address the poor communications on the
- CDocument mitigations to the security concerns and facilitate a meeting between the
- DDevelop a proposal for an alternative architecture that does not leverage cloud computing
How the community answered
(25 responses)- A12% (3)
- B20% (5)
- C64% (16)
- D4% (1)
Why each option
When security risks are ignored due to communication failures, the network engineer should document mitigations formally and facilitate dialogue between the relevant architects.
Addressing security concerns solely through network design is too narrow in scope and does not resolve the organizational communication breakdown causing the broader system security risks to be ignored.
Unilaterally implementing mitigations without stakeholder alignment exceeds the network engineer's authority and does not fix the underlying communication problem between the architects.
Documenting the security concerns and proposed mitigations creates a formal record that cannot be ignored, while facilitating a meeting between the security architect and systems architect addresses the root cause - poor communication - through proper professional channels without exceeding the network engineer's organizational role or authority.
Proposing an entirely different architecture that eliminates cloud computing is an extreme, out-of-scope action that does not address the immediate security risks or the communication failure within the existing team.
Concept tested: Security risk escalation and stakeholder communication in system projects
Source: https://csrc.nist.gov/publications/detail/sp/800-160/vol-1/rev-1/final
Topics
Community Discussion
No community discussion yet for this question.