CAS-002 · Question #252
A new internal network segmentation solution will be implemented into the enterprise that consists of 200 internal firewalls. As part of running a pilot exercise, it was determined that it takes…
The correct answer is D. Review to determine if control effectiveness is in line with the complexity of the solution. When security controls introduce significant operational complexity - such as requiring three change requests per application deployment across 200 firewalls - the first step is to evaluate whether the control's effectiveness justifies that complexity.
Question
A new internal network segmentation solution will be implemented into the enterprise that consists of 200 internal firewalls. As part of running a pilot exercise, it was determined that it takes three changes to deploy a new application onto the network before it is operational. Security now has a significant affect on overall availability. Which of the following would be the FIRST process to perform as a result of these findings?
Options
- ALower the SLA to a more tolerable level and perform a risk assessment to see if the solution
- BPerform a cost benefit analysis and implement the solution as it stands as long as the risks
- CEngage internal auditors to perform a review of the project to determine why and how the
- DReview to determine if control effectiveness is in line with the complexity of the solution.
How the community answered
(22 responses)- A5% (1)
- B23% (5)
- C9% (2)
- D64% (14)
Why each option
When security controls introduce significant operational complexity - such as requiring three change requests per application deployment across 200 firewalls - the first step is to evaluate whether the control's effectiveness justifies that complexity.
Lowering the SLA before understanding whether the controls are even effective is premature and could lock the organization into accepting reduced availability without confirming any security benefit.
Performing a cost-benefit analysis before confirming whether the controls actually work as intended produces unreliable conclusions because the effectiveness variable is unknown.
Engaging internal auditors to review the project is a reactive escalation step that is premature before the security team has first assessed the technical alignment between control design and business requirements.
Before taking any corrective or escalation action, security professionals must first assess whether the implemented controls are achieving their intended security objectives proportionate to the operational burden they impose. Reviewing control effectiveness against solution complexity allows the organization to make an informed decision about whether the current design is appropriate, over-engineered, or needs tuning - this analysis must precede any SLA changes, cost-benefit work, or audit engagement.
Concept tested: Security control effectiveness review vs operational complexity
Source: https://csrc.nist.gov/publications/detail/sp/800-53/rev-5/final
Topics
Community Discussion
No community discussion yet for this question.