CompTIA SecurityX (CAS-005)Governance, Risk and ComplianceMedium

A recent audit report identified that several critical systems lack adequate logging for security events, making incident investigation difficult and compliance reporting incomplete. The CISO needs to address this finding by implementing a comprehensive logging strategy across the enterprise. Which of the following risk management steps should the CISO prioritize IMMEDIATELY after identifying this gap?

  1. AImplement a Security Information and Event Management (SIEM) system.
  2. BConduct a Business Impact Analysis (BIA) for affected systems.
  3. CDevelop a remediation plan with timelines and assigned responsibilities.
  4. DAssess the likelihood and impact of the identified logging gap.
Show answer & explanation

Correct answer: D. Assess the likelihood and impact of the identified logging gap.

After identifying a security gap or risk, the immediate next step in a structured risk management process is to assess the risk. This involves determining the likelihood of the risk occurring and its potential impact, which helps in prioritizing subsequent actions. Without this assessment, implementing solutions (A) or developing remediation plans (D) might be misdirected or inefficient.

Why the other options are wrong

  • A. Implementing a SIEM is a mitigation control, but it should follow a proper risk assessment to ensure it's the most appropriate and prioritized solution.
  • B. A BIA is crucial for understanding the impact of disruptions, but the immediate focus after identifying a security gap is to assess the risk of that specific gap, not necessarily a full BIA which is broader.
  • C. Developing a remediation plan is a subsequent step that relies on the outcomes of the risk assessment to define appropriate actions and timelines.

Risk Assessment (Quantitative)

The process of identifying, analyzing, and evaluating risks. Quantitative risk assessment assigns numerical values to risk components (asset value, exposure factor, ARO) to calculate potential financial loss.

  • Identifies and evaluates risks.
  • Determines likelihood and impact.
  • Informs prioritization of mitigation efforts.

Memory trick: I-A-R-M-M: Identify, Assess, Respond, Monitor, Maintain.

More Governance, Risk and Compliance questions