nerdexam
Isaca

CISM · Question #584

A small organization needs to use a solution that is out of support in order to meet business objectives. Which of the following is the information security manager's BEST course of action to manage…

The correct answer is D. Implement compensating security controls. When a solution must be used despite being out of support, the best course of action is to implement compensating controls to mitigate the associated risks and maintain an acceptable security posture.

Submitted by kim_seoul· Apr 18, 2026Information Security Risk Management

Question

A small organization needs to use a solution that is out of support in order to meet business objectives. Which of the following is the information security manager's BEST course of action to manage the associated risk?

Options

  • AAdvise business units to change the system.
  • BRecommend the risk be accepted by senior leadership.
  • CRun periodic vulnerability scans.
  • DImplement compensating security controls.

How the community answered

(38 responses)
  • A
    18% (7)
  • B
    8% (3)
  • C
    3% (1)
  • D
    71% (27)

Explanation

When a solution must be used despite being out of support, the best course of action is to implement compensating controls to mitigate the associated risks and maintain an acceptable security posture.

Topics

#Risk Mitigation#Compensating Controls#Unsupported Systems#Risk Management Strategies

Community Discussion

No community discussion yet for this question.

Full CISM Practice