nerdexam
CompTIA

CAS-003 · Question #887

A small company is implementing a new technology that promises greater performance but does not abide by accepted RFCs. Which of the following should the company do to ensure the risks associated…

The correct answer is A. Document the technology's differences in a system security plan. When a technology deviates from accepted RFCs, the formal risk management response is to document those deviations in a System Security Plan (SSP). The SSP is a governance artifact (central to frameworks like NIST RMF and FedRAMP) that records a system's security controls…

Risk Management

Question

A small company is implementing a new technology that promises greater performance but does not abide by accepted RFCs. Which of the following should the company do to ensure the risks associated with Implementing the standard-violating technology is addressed?

Options

  • ADocument the technology's differences in a system security plan.
  • BRequire the vendor to provide justification for the product's deviation.
  • CIncrease the frequency of vulnerability scanning of all systems using the technology.
  • DBlock the use of non-standard ports or protocols to and from the system.

How the community answered

(48 responses)
  • A
    79% (38)
  • B
    6% (3)
  • C
    10% (5)
  • D
    4% (2)

Explanation

When a technology deviates from accepted RFCs, the formal risk management response is to document those deviations in a System Security Plan (SSP). The SSP is a governance artifact (central to frameworks like NIST RMF and FedRAMP) that records a system's security controls, configurations, and any exceptions or deviations from standards. Documenting the differences ensures the risk is formally acknowledged, visible to security reviewers and auditors, and subject to an explicit risk acceptance decision by the appropriate authority. Option B (vendor justification) is a useful input but does not itself mitigate or manage the risk. Option C (increased scanning) is a detective control that doesn't address the underlying deviation. Option D (blocking non-standard ports) is overly prescriptive and may not even apply to the deviation in question.

Topics

#vendor risk#non-standard protocols#system security plan#risk documentation

Community Discussion

No community discussion yet for this question.

Full CAS-003 Practice