A security auditor is reviewing an organization's patch management policy. The policy states that 'critical security patches must be applied to production systems within 72 hours of release, provided they pass staging environment testing.' However, the auditor discovers that due to resource constraints and complex interdependencies, many critical patches are routinely delayed for weeks. What is the auditor's most significant concern regarding this discrepancy?
- AThe policy is too aggressive and should be revised to reflect realistic timelines.
- BThe organization is non-compliant with its own security policy, increasing risk exposure.
- CThe staging environment testing process is inefficient and needs optimization.
- DThe security team lacks sufficient automation tools for patch deployment.
Show answer & explanationAnswer & explanation
Correct answer: B. The organization is non-compliant with its own security policy, increasing risk exposure.
The most significant concern is the non-compliance with the organization's own documented policy. This indicates a breakdown in governance and significantly increases the organization's risk exposure, as critical vulnerabilities remain unpatched for extended periods despite a stated commitment to rapid remediation. While other options might be contributing factors, the core issue is the failure to adhere to the policy.
Why the other options are wrong
- A. While policy revision might be a solution, the immediate concern is the failure to follow the existing policy, which implies increased risk.
- C. Inefficiency in testing is a root cause, but the immediate and most significant concern is the consequence of that inefficiency: policy violation and risk.
- D. Lack of automation is a potential root cause, but the policy violation and resulting risk are the primary concerns for an auditor.
Policy Non-Compliance (Patch Management)
A situation where an organization fails to adhere to its defined patch management policies and procedures, often leading to increased exposure to known security vulnerabilities.
- Indicates a gap between policy and practice.
- Significantly increases organizational risk.
- Can result in audit findings and regulatory penalties.
Memory trick: Policy says 'A', practice does 'B', risk is high for all to see.