Certified Information Security Manager (CISM)Information Security Risk ManagementMedium

During a routine security audit, several critical vulnerabilities are identified in a legacy application that is essential for core business operations. Due to the application's age and complexity, immediate patching would require extensive re-engineering, which is not feasible within the acceptable timeframe. The information security manager needs to implement a temporary solution to reduce the risk while a long-term fix is developed. Which of the following is the MOST appropriate immediate risk treatment strategy?

  1. AAccepting the risk, as the cost of immediate remediation is too high.
  2. BTransferring the risk by purchasing a comprehensive cyber insurance policy.
  3. CAvoiding the risk by immediately decommissioning the legacy application.
  4. DImplementing compensating controls, such as network segmentation and enhanced monitoring.
Show answer & explanation

Correct answer: D. Implementing compensating controls, such as network segmentation and enhanced monitoring.

When direct remediation is not immediately feasible, implementing compensating controls is the most appropriate strategy. These controls act as temporary or alternative safeguards to reduce the risk posed by the vulnerability until a permanent solution can be applied.

Why the other options are wrong

  • A. Accepting the risk without mitigation is generally not preferred for critical vulnerabilities, especially when temporary measures are possible.
  • B. Cyber insurance transfers financial risk, but it doesn't reduce the likelihood or impact of an attack itself, nor does it address the immediate operational risk.
  • C. Decommissioning a critical application immediately is often not feasible or desirable due to business continuity impacts.

Compensating Controls

Alternative security controls that are implemented to meet the intent of a security requirement when the primary control cannot be implemented or is not fully effective.

  • Used when primary control is not feasible.
  • Reduces risk to an acceptable level.
  • Often temporary until a permanent solution.

Memory trick: Compensating Controls: A temporary fix to bridge the gap.

More Information Security Risk Management questions