CISM · Question #333
An organization has determined that fixing a security vulnerability in a critical application is too costly to be feasible, but the impact is material to the business. Which of the following is the MO
The correct answer is C. Implement compensating controls for the application.. When full remediation is cost-prohibitive but the risk impact is material, compensating controls are the most appropriate treatment because they actively reduce the likelihood or impact of exploitation without requiring the costly fix. This is preferable to simply accepting or tr
Question
An organization has determined that fixing a security vulnerability in a critical application is too costly to be feasible, but the impact is material to the business. Which of the following is the MOST appropriate risk treatment?
Options
- ADiscontinue using the application.
- BAccept the risk associated with continued use of the application.
- CImplement compensating controls for the application.
- DPurchase cybersecurity insurance.
How the community answered
(23 responses)- A4% (1)
- B9% (2)
- C78% (18)
- D9% (2)
Explanation
When full remediation is cost-prohibitive but the risk impact is material, compensating controls are the most appropriate treatment because they actively reduce the likelihood or impact of exploitation without requiring the costly fix. This is preferable to simply accepting or transferring the risk when impact is significant. Discontinuing the application (A) is not viable if it is described as critical. Accepting the risk (B) is inappropriate when the impact is explicitly described as material to the business. Cybersecurity insurance (D) transfers only financial consequences and does not reduce the probability or technical impact of an incident.
Topics
Community Discussion
No community discussion yet for this question.