CISM · Question #770
A serious vulnerability was detected in a business application that can be exploited by external attackers to compromise the system. What is the information security manager's BEST course of action?
The correct answer is C. Report the risk to the business application owner. Why C is correct: The information security manager's role is to identify, assess, and communicate risk - not to unilaterally make operational decisions about systems they don't own. Reporting the vulnerability to the business application owner ensures the right decision-maker…
Question
A serious vulnerability was detected in a business application that can be exploited by external attackers to compromise the system. What is the information security manager's BEST course of action?
Options
- AImplement temporary remediation.
- BAsk the business application owner to apply the fix immediately.
- CReport the risk to the business application owner.
- DImmediately shut down the application.
How the community answered
(17 responses)- A6% (1)
- C82% (14)
- D12% (2)
Explanation
Why C is correct: The information security manager's role is to identify, assess, and communicate risk - not to unilaterally make operational decisions about systems they don't own. Reporting the vulnerability to the business application owner ensures the right decision-maker is informed and can weigh the business impact before acting. This follows the principle of risk ownership: the person accountable for the asset is accountable for accepting or remediating the risk.
Why the distractors fail:
- A (temporary remediation): The security manager doesn't own the application and shouldn't apply fixes independently - that's the owner's call, and premature action could cause unintended downtime or break functionality.
- B (ask owner to apply fix immediately): This oversteps - dictating how to respond bypasses risk assessment and may not account for business constraints like change windows or testing requirements. The owner decides the response, not the security team.
- D (shut it down immediately): Shutting down a business application is a major operational decision that belongs to the business owner, not the security manager. Unilateral shutdown could cause more business damage than the vulnerability itself.
Memory tip: Think of the security manager as a risk reporter, not a risk resolver. When in doubt on CISM/CISSP-style questions, the security function identifies and communicates risk upward to the asset owner - it doesn't act on assets it doesn't own.
Topics
Community Discussion
No community discussion yet for this question.