CISM · Question #299
A business unit is not complying with a control implemented to mitigate risk because doing so impacts the ability to achieve business goals. When reporting the noncompliance to senior management…
The correct answer is B. Implement compensating controls. Implementing compensating controls (B) is the best recommendation because it addresses both sides of the conflict: the original risk is still mitigated through alternative measures, while the business unit retains the ability to meet its operational goals. When a control is…
Question
A business unit is not complying with a control implemented to mitigate risk because doing so impacts the ability to achieve business goals. When reporting the noncompliance to senior management, what would be the information security manager's BEST recommendation?
Options
- AModify the exception process.
- BImplement compensating controls.
- CConduct a gap analysis.
- DEducate the noncompliant users.
How the community answered
(40 responses)- A5% (2)
- B78% (31)
- C13% (5)
- D5% (2)
Explanation
Implementing compensating controls (B) is the best recommendation because it addresses both sides of the conflict: the original risk is still mitigated through alternative measures, while the business unit retains the ability to meet its operational goals. When a control is technically sound but operationally disruptive, compensating controls provide an equivalent level of protection without forcing a binary "comply or accept risk" choice - making this the most balanced and actionable recommendation to senior management.
Why the distractors fall short:
- A (Modify the exception process) deals with how exceptions are handled procedurally, not with actually mitigating the underlying risk - it's an administrative fix, not a security fix.
- C (Conduct a gap analysis) is a discovery activity to identify what controls are missing; the gap here is already known, so this is redundant and delays action.
- D (Educate noncompliant users) assumes the problem is ignorance, but the scenario explicitly states noncompliance stems from business impact, not lack of awareness - training won't resolve a conflict of objectives.
Memory tip: Think of compensating controls as the "yes, and..." answer - yes, the original control doesn't work here, and we can still manage the risk another way. On the exam, when a control conflicts with business operations, the answer almost always involves finding an alternative path to the same security outcome rather than forcing compliance or accepting the gap.
Topics
Community Discussion
No community discussion yet for this question.