CAS-002 · Question #872
ODBC access to a database on a network-connected host is required. The host does not have a security mechanism to authenticate the incoming ODBC connection, and the application requires that the…
The correct answer is B. Explain the risks to the data owner and aid in the decision to accept the risk versus choosing a. When a system presents risk due to unauthenticated ODBC access, the security analyst must explain the risks to the data owner and support an informed risk acceptance decision.
Question
ODBC access to a database on a network-connected host is required. The host does not have a security mechanism to authenticate the incoming ODBC connection, and the application requires that the connection have read/write permissions. In order to further secure the data, a nonstandard configuration would need to be implemented. The information in the database is not sensitive, but was not readily accessible prior to the implementation of the ODBC connection. Which of the following actions should be taken by the security analyst?
Options
- AAccept the risk in order to keep the system within the company's standard security configuration.
- BExplain the risks to the data owner and aid in the decision to accept the risk versus choosing a
- CSecure the data despite the need to use a security control or solution that is not within company
- DDo not allow the connection to be made to avoid unnecessary risk and avoid deviating from the
How the community answered
(31 responses)- A10% (3)
- B68% (21)
- C3% (1)
- D19% (6)
Why each option
When a system presents risk due to unauthenticated ODBC access, the security analyst must explain the risks to the data owner and support an informed risk acceptance decision.
Accepting risk without involving the data owner bypasses proper governance and removes the responsible party's ability to make an informed decision about risks to their own data.
The data owner holds authority and accountability for decisions regarding their data, so the security analyst's role is to explain the technical risks clearly and help the data owner make an informed decision between accepting the risk or implementing a nonstandard control - this follows proper risk governance and avoids unilateral decisions that ignore business context.
Implementing nonstandard security controls without data owner involvement and proper change management exceeds the security analyst's authority and skips required approval processes.
Blocking the connection without consulting the data owner is a unilateral decision that ignores legitimate business requirements and does not follow proper risk management procedures.
Concept tested: Risk acceptance and data owner responsibility
Source: https://csrc.nist.gov/publications/detail/sp/800-37/rev-2/final
Topics
Community Discussion
No community discussion yet for this question.