CAS-002 · Question #243
The Universal Research Association has just been acquired by the Association of Medical Business Researchers. The new conglomerate has funds to upgrade or replace hardware as part of the…
The correct answer is C. Industry security standards and regulations may be in conflict. When hardware can be replaced but software projects cannot be funded post-acquisition, conflicting industry security standards and regulatory requirements will most likely block full IT integration.
Question
The Universal Research Association has just been acquired by the Association of Medical Business Researchers. The new conglomerate has funds to upgrade or replace hardware as part of the acquisition, but cannot fund labor for major software projects. Which of the following will MOST likely result in some IT resources not being integrated?
Options
- AOne of the companies may use an outdated VDI.
- BCorporate websites may be optimized for different web browsers.
- CIndustry security standards and regulations may be in conflict.
- DData loss prevention standards in one company may be less stringent.
How the community answered
(25 responses)- A4% (1)
- B8% (2)
- C84% (21)
- D4% (1)
Why each option
When hardware can be replaced but software projects cannot be funded post-acquisition, conflicting industry security standards and regulatory requirements will most likely block full IT integration.
Outdated VDI infrastructure can be replaced using the hardware budget that is available under the acquisition terms, making this a solvable problem within the stated funding constraints.
Website browser optimization is a low-effort cosmetic concern that does not prevent IT resource integration and requires no major software project to address.
A research organization and a medical business organization may operate under fundamentally different and potentially incompatible regulatory regimes - for example HIPAA for medical data versus research-specific frameworks - and reconciling these compliance requirements would demand significant software development that falls outside the available funding, leaving IT systems that cannot be made compliant under both regimes unable to be integrated.
Differences in DLP policy stringency represent a configuration and policy alignment gap that can typically be resolved by raising the less stringent standard through administrative changes rather than major software development.
Concept tested: Post-acquisition IT integration regulatory conflict barriers
Source: https://csrc.nist.gov/publications/detail/sp/800-37/rev-2/final
Topics
Community Discussion
No community discussion yet for this question.