CISM · Question #27
Which of the following is the PRIMARY reason for granting a security exception?
The correct answer is C. The risk is justified by the benefit to the business. A security exception is primarily granted when the inherent security risk is deemed acceptable because the business benefits gained by allowing the deviation outweigh the potential consequences of the risk.
Question
Which of the following is the PRIMARY reason for granting a security exception?
Options
- AThe risk is justified by the cost to security.
- BThe risk is justified by the benefit to security.
- CThe risk is justified by the benefit to the business.
- DThe risk is justified by the cost to the business.
How the community answered
(40 responses)- A3% (1)
- B3% (1)
- C88% (35)
- D8% (3)
Why each option
A security exception is primarily granted when the inherent security risk is deemed acceptable because the business benefits gained by allowing the deviation outweigh the potential consequences of the risk.
"The risk is justified by the cost to security" is circular and illogical; security costs are incurred to manage risk, not justify it.
"The risk is justified by the benefit to security" implies that taking a risk would somehow enhance security, which is generally not the case for an exception.
Security exceptions are granted when the identified security risk, after thorough assessment, is demonstrably outweighed by a significant business benefit, such as enabling a critical project or maintaining essential operations that would otherwise be halted. This decision acknowledges the risk but prioritizes business enablement under controlled conditions.
"The risk is justified by the cost to the business" suggests taking a risk because it's expensive not to, which is part of the cost-benefit analysis but doesn't fully capture the benefit aspect that justifies the exception.
Concept tested: Security exception rationale
Topics
Community Discussion
No community discussion yet for this question.