Certified Information Security Manager (CISM)Information Security Risk ManagementMedium

During a routine vulnerability scan, the information security manager identifies several critical vulnerabilities on a legacy system that supports a non-critical, internal business function. The vendor no longer provides security patches for this system, and replacement is budgeted for next year. Which of the following is the MOST appropriate interim control strategy?

  1. ADevelop custom patches for the legacy system using internal resources.
  2. BAccept the risk, as the system is non-critical and replacement is planned.
  3. CImmediately replace the system, reallocating funds from other projects.
  4. DIsolate the legacy system from the main network and implement compensating controls.
Show answer & explanation

Correct answer: D. Isolate the legacy system from the main network and implement compensating controls.

Since the system is legacy and unpatchable, and immediate replacement is not feasible, the most appropriate interim control is to isolate it to limit its attack surface and impact, and implement compensating controls (e.g., strict access controls, monitoring) to reduce the risk until it can be replaced.

Why the other options are wrong

  • A. Developing custom patches for unsupported systems is usually complex, expensive, and often unreliable, making it an impractical interim solution.
  • B. Accepting critical vulnerabilities, even on a non-critical system, without any mitigation is often not acceptable, especially when interim controls are possible.
  • C. Immediate replacement is not feasible due to budget constraints.

Compensating Controls

Security controls implemented to address a requirement that cannot be met by standard controls, often used for legacy systems or specific operational needs.

  • Provide equivalent protection to primary controls.
  • Often involve administrative or technical measures.
  • Used when direct mitigation is not feasible.

Memory trick: Old systems, new risks: isolate and compensate.

More Information Security Risk Management questions