nerdexam
CompTIA

CAS-003 · Question #179

The Information Security Officer (ISO) is reviewing new policies that have been recently made effective and now apply to the company. Upon review, the ISO identifies a new requirement to implement…

The correct answer is A. Business or technical justification for not implementing the requirements. B. Risks associated with the inability to implement the requirements. G. Current and planned controls to mitigate the risks. The Exception Request must include: A description of the non-compliance. The anticipated length of non-compliance (2-year maximum). The proposed assessment of risk associated with non-compliance. The proposed plan for managing the risk associated with non- compliance. The…

Risk Management

Question

The Information Security Officer (ISO) is reviewing new policies that have been recently made effective and now apply to the company. Upon review, the ISO identifies a new requirement to implement two-factor authentication on the company's wireless system. Due to budget constraints, the company will be unable to implement the requirement for the next two years. The ISO is required to submit a policy exception form to the Chief Information Officer (CIO). Which of the following are MOST important to include when submitting the exception form? (Select THREE).

Options

  • ABusiness or technical justification for not implementing the requirements.
  • BRisks associated with the inability to implement the requirements.
  • CIndustry best practices with respect to the technical implementation of the current controls.
  • DAll sections of the policy that may justify non-implementation of the requirements.
  • EA revised DRP and COOP plan to the exception form.
  • FInternal procedures that may justify a budget submission to implement the new requirement.
  • GCurrent and planned controls to mitigate the risks.

How the community answered

(28 responses)
  • A
    43% (12)
  • C
    14% (4)
  • D
    7% (2)
  • E
    32% (9)
  • F
    4% (1)

Explanation

The Exception Request must include: A description of the non-compliance. The anticipated length of non-compliance (2-year maximum). The proposed assessment of risk associated with non-compliance. The proposed plan for managing the risk associated with non- compliance. The proposed metrics for evaluating the success of risk management (if risk is significant). The proposed review date to evaluate progress toward compliance. An endorsement of the request by the appropriate Information Trustee (VP or Dean).

Topics

#policy exception#risk acceptance#compensating controls#two-factor authentication

Community Discussion

No community discussion yet for this question.

Full CAS-003 Practice