CISA · Question #62
An IS auditor finds that firewalls are outdated and not supported by vendors. Which of the following should be the auditor's NEXT course of action?
The correct answer is B. Determine the risk of not replacing the firewall.. Upon discovering outdated and unsupported firewalls, the IS auditor's immediate next step should be to determine the specific risks these vulnerabilities pose to the organization.
Question
An IS auditor finds that firewalls are outdated and not supported by vendors. Which of the following should be the auditor’s NEXT course of action?
Options
- AReport the security posture of the organization.
- BDetermine the risk of not replacing the firewall.
- CReport the mitigating controls.
- DDetermine the value of the firewall.
How the community answered
(32 responses)- A3% (1)
- B78% (25)
- C6% (2)
- D13% (4)
Why each option
Upon discovering outdated and unsupported firewalls, the IS auditor's immediate next step should be to determine the specific risks these vulnerabilities pose to the organization.
Reporting the security posture of the organization should only occur after understanding the level of risk, as the report needs to accurately reflect the severity and implications of the outdated firewalls.
Determining the risk involves evaluating the likelihood of an outdated, unsupported firewall being exploited and the potential impact of such an exploitation on the organization's assets and operations. This risk assessment provides the necessary context and justification for subsequent reporting and remediation recommendations, making it the critical step after identifying the deficiency.
Concept tested: Auditor's response to security vulnerabilities
Source: https://nvlpubs.nist.gov/nistpubs/legacy/sp/nistspecialpublication800-30r1.pdf
Topics
Community Discussion
No community discussion yet for this question.