nerdexam
Isaca

CISM · Question #333

An organization has determined that fixing a security vulnerability in a critical application is too costly to be feasible, but the impact is material to the business. Which of the following is the MO

The correct answer is C. Implement compensating controls for the application.. When full remediation is cost-prohibitive but the risk impact is material, compensating controls are the most appropriate treatment because they actively reduce the likelihood or impact of exploitation without requiring the costly fix. This is preferable to simply accepting or tr

Submitted by takeshi77· Apr 18, 2026Information Security Risk Management

Question

An organization has determined that fixing a security vulnerability in a critical application is too costly to be feasible, but the impact is material to the business. Which of the following is the MOST appropriate risk treatment?

Options

  • ADiscontinue using the application.
  • BAccept the risk associated with continued use of the application.
  • CImplement compensating controls for the application.
  • DPurchase cybersecurity insurance.

How the community answered

(23 responses)
  • A
    4% (1)
  • B
    9% (2)
  • C
    78% (18)
  • D
    9% (2)

Explanation

When full remediation is cost-prohibitive but the risk impact is material, compensating controls are the most appropriate treatment because they actively reduce the likelihood or impact of exploitation without requiring the costly fix. This is preferable to simply accepting or transferring the risk when impact is significant. Discontinuing the application (A) is not viable if it is described as critical. Accepting the risk (B) is inappropriate when the impact is explicitly described as material to the business. Cybersecurity insurance (D) transfers only financial consequences and does not reduce the probability or technical impact of an incident.

Topics

#Risk treatment#Compensating controls#Risk mitigation#Risk acceptance

Community Discussion

No community discussion yet for this question.

Full CISM Practice