CAS-002 · Question #635
The Chief Executive Officer (CEO) of a corporation purchased the latest mobile device and wants to connect it to the internal network. The Chief Information Security Officer (CISO) was told to…
The correct answer is A. Mitigate and Transfer. This question tests risk response strategy selection when a required business activity introduces security risk. Since the CEO mandates the access, avoidance is not an option.
Question
The Chief Executive Officer (CEO) of a corporation purchased the latest mobile device and wants to connect it to the internal network. The Chief Information Security Officer (CISO) was told to research and recommend how to secure this device. Which of the following should be implemented, keeping in mind that the CEO has stated that this access is required?
Options
- AMitigate and Transfer
- BAccept and Transfer
- CTransfer and Avoid
- DAvoid and Mitigate
How the community answered
(53 responses)- A74% (39)
- B4% (2)
- C9% (5)
- D13% (7)
Why each option
This question tests risk response strategy selection when a required business activity introduces security risk. Since the CEO mandates the access, avoidance is not an option.
Mitigate involves implementing security controls such as MDM, containerization, or device enrollment policies to reduce the risk posed by the unmanaged mobile device. Transfer shifts the residual risk to a third party, such as through cyber insurance. Together these two strategies address the risk without blocking the CEO's required access.
Accept means acknowledging the risk without taking action to reduce it, which is inappropriate when technical controls can and should be applied to a high-profile executive device.
Transfer alone is insufficient without mitigation controls, and Avoid means eliminating the activity entirely, which directly contradicts the CEO's stated requirement for access.
Avoid is not viable because the CEO has mandated the access, making it impossible to eliminate the risk by refusing the connection.
Concept tested: Risk response strategies - mitigate and transfer
Source: https://csrc.nist.gov/publications/detail/sp/800-37/rev-2/final
Topics
Community Discussion
No community discussion yet for this question.