SY0-501 · Question #395
A security architect has convened a meeting to discuss an organization's key management policy. The organization has a reliable internal key management system, and some argue that it would be best…
The correct answer is C. risk benefits analysis results to make a determination. The organization should make its key management system decision based on a thorough risk-benefit analysis, rather than defaulting to an existing system or solely considering cost savings.
Question
A security architect has convened a meeting to discuss an organization's key management policy. The organization has a reliable internal key management system, and some argue that it would be best to manage the cryptographic keys internally as opposed to using a solution from a third party. The company should use:
Options
- Athe current internal key management system.
- Ba third-party key management system that will reduce operating costs.
- Crisk benefits analysis results to make a determination.
- Da software solution including secure key escrow capabilities.
How the community answered
(45 responses)- A13% (6)
- B7% (3)
- C78% (35)
- D2% (1)
Why each option
The organization should make its key management system decision based on a thorough risk-benefit analysis, rather than defaulting to an existing system or solely considering cost savings.
Simply continuing with the current internal key management system without evaluating alternatives or current security posture might lead to missed opportunities for improved security or efficiency, or expose the organization to unaddressed risks.
While cost reduction is a factor, making a critical security decision solely on the basis of reducing operating costs, without a broader assessment of security, reliability, and strategic alignment, is an incomplete and potentially risky approach.
When evaluating critical security infrastructure like a key management system, a comprehensive approach is essential. A risk-benefit analysis systematically evaluates the potential security risks, operational benefits, compliance implications, and costs associated with both internal and third-party solutions. This data-driven methodology ensures that the final decision aligns with the organization's overall risk appetite, security posture, and business objectives, providing a defensible rationale for the chosen key management strategy.
Key escrow capabilities are a specific feature of a key management system, but this choice does not provide a methodology for deciding between fundamental key management strategies (internal vs. third-party) or address the broader security and operational context.
Concept tested: Strategic security decision-making through risk-benefit analysis
Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-30r1.pdf
Topics
Community Discussion
No community discussion yet for this question.