CAS-002 · Question #588
A business owner has raised concerns with the Chief Information Security Officer (CISO) because money has been spent on IT security infrastructure, but corporate assets are still found to be…
The correct answer is D. Security controls are generally never 100% effective and gaps should be explained to. No security control is 100% effective, and the CISO must communicate this inherent limitation to business stakeholders when audit gaps are found despite implemented controls.
Question
A business owner has raised concerns with the Chief Information Security Officer (CISO) because money has been spent on IT security infrastructure, but corporate assets are still found to be vulnerable. The business recently implemented a patch management product and SOE hardening initiative. A third party auditor reported findings against the business because some systems were missing patches. Which of the following statements BEST describes this situation?
Options
- AThe business owner is at fault because they are responsible for patching the systems and
- BThe audit findings are invalid because remedial steps have already been applied to patch
- CThe CISO has not selected the correct controls and the audit findings should be assigned to
- DSecurity controls are generally never 100% effective and gaps should be explained to
How the community answered
(36 responses)- A8% (3)
- B17% (6)
- C31% (11)
- D44% (16)
Why each option
No security control is 100% effective, and the CISO must communicate this inherent limitation to business stakeholders when audit gaps are found despite implemented controls.
The business owner is not operationally responsible for patching systems - that responsibility belongs to IT and security teams who manage the patch management product.
Audit findings reflect the state of systems at the time of assessment and remain valid even if remediation began after the audit period.
The controls selected - patch management and SOE hardening - are appropriate for the identified risk; the issue is control effectiveness and coverage, not control selection.
Security controls such as patch management and SOE hardening reduce risk but cannot eliminate it entirely - coverage gaps, timing windows, and configuration drift mean some systems will remain exposed. The CISO's responsibility includes educating business owners on residual risk so they can make informed decisions about acceptable risk tolerance.
Concept tested: Residual risk and security control effectiveness
Source: https://csrc.nist.gov/publications/detail/sp/800-30/rev-1/final
Topics
Community Discussion
No community discussion yet for this question.