nerdexam
CompTIA

CAS-002 · Question #588

A business owner has raised concerns with the Chief Information Security Officer (CISO) because money has been spent on IT security infrastructure, but corporate assets are still found to be…

The correct answer is D. Security controls are generally never 100% effective and gaps should be explained to. No security control is 100% effective, and the CISO must communicate this inherent limitation to business stakeholders when audit gaps are found despite implemented controls.

Integration of Computing, Communications and Business Disciplines

Question

A business owner has raised concerns with the Chief Information Security Officer (CISO) because money has been spent on IT security infrastructure, but corporate assets are still found to be vulnerable. The business recently implemented a patch management product and SOE hardening initiative. A third party auditor reported findings against the business because some systems were missing patches. Which of the following statements BEST describes this situation?

Options

  • AThe business owner is at fault because they are responsible for patching the systems and
  • BThe audit findings are invalid because remedial steps have already been applied to patch
  • CThe CISO has not selected the correct controls and the audit findings should be assigned to
  • DSecurity controls are generally never 100% effective and gaps should be explained to

How the community answered

(36 responses)
  • A
    8% (3)
  • B
    17% (6)
  • C
    31% (11)
  • D
    44% (16)

Why each option

No security control is 100% effective, and the CISO must communicate this inherent limitation to business stakeholders when audit gaps are found despite implemented controls.

AThe business owner is at fault because they are responsible for patching the systems and

The business owner is not operationally responsible for patching systems - that responsibility belongs to IT and security teams who manage the patch management product.

BThe audit findings are invalid because remedial steps have already been applied to patch

Audit findings reflect the state of systems at the time of assessment and remain valid even if remediation began after the audit period.

CThe CISO has not selected the correct controls and the audit findings should be assigned to

The controls selected - patch management and SOE hardening - are appropriate for the identified risk; the issue is control effectiveness and coverage, not control selection.

DSecurity controls are generally never 100% effective and gaps should be explained toCorrect

Security controls such as patch management and SOE hardening reduce risk but cannot eliminate it entirely - coverage gaps, timing windows, and configuration drift mean some systems will remain exposed. The CISO's responsibility includes educating business owners on residual risk so they can make informed decisions about acceptable risk tolerance.

Concept tested: Residual risk and security control effectiveness

Source: https://csrc.nist.gov/publications/detail/sp/800-30/rev-1/final

Topics

#patch management#security controls#audit findings#risk management

Community Discussion

No community discussion yet for this question.

Full CAS-002 Practice