nerdexam
CompTIA

CAS-002 · Question #876

An information security assessor for an organization finished an assessment that identified critical issues with the human resource new employee management software application. The assessor…

The correct answer is C. Schedule a meeting with key human resource application stakeholders. When a security assessment report is ignored by senior management, engaging the relevant application stakeholders directly is the logical next step to drive remediation action.

Integration of Computing, Communications and Business Disciplines

Question

An information security assessor for an organization finished an assessment that identified critical issues with the human resource new employee management software application. The assessor submitted the report to senior management but nothing has happened. Which of the following would be a logical next step?

Options

  • AMeet the two key VPs and request a signature on the original assessment.
  • BInclude specific case studies from other organizations in an updated report.
  • CSchedule a meeting with key human resource application stakeholders.
  • DCraft an RFP to begin finding a new human resource application.

How the community answered

(22 responses)
  • A
    5% (1)
  • B
    9% (2)
  • C
    82% (18)
  • D
    5% (1)

Why each option

When a security assessment report is ignored by senior management, engaging the relevant application stakeholders directly is the logical next step to drive remediation action.

AMeet the two key VPs and request a signature on the original assessment.

Requesting VP signatures on the original assessment is a procedural step that does not directly advance remediation and may bypass the appropriate application owners who manage the system day-to-day.

BInclude specific case studies from other organizations in an updated report.

Including case studies from other organizations adds supporting context but does not directly engage the stakeholders responsible for acting on the findings.

CSchedule a meeting with key human resource application stakeholders.Correct

Scheduling a meeting with key HR application stakeholders is the most effective next step because it brings together the decision-makers who own the affected system and have the authority to approve remediation. Direct stakeholder engagement creates accountability, allows the assessor to present findings in context, and builds the organizational momentum needed to prioritize and fund fixes.

DCraft an RFP to begin finding a new human resource application.

Crafting an RFP to replace the application is premature and assumes a replacement decision has been made before any stakeholder discussion has occurred about the assessment findings.

Concept tested: Security assessment stakeholder engagement and remediation follow-up

Source: https://csrc.nist.gov/publications/detail/sp/800-115/final

Topics

#security assessment#stakeholder engagement#risk communication#governance

Community Discussion

No community discussion yet for this question.

Full CAS-002 Practice