Certified Information Security Manager (CISM)Information Security Risk ManagementHard
A financial institution is implementing a new online banking platform. During the risk assessment, the information security manager identifies a high-risk vulnerability related to unpatched legacy components within the platform's infrastructure. The cost to patch these components immediately is significant and will delay the platform's launch. The business leadership is unwilling to accept the delay. What is the MOST appropriate information security management response?
- AAccept the risk, document it, and proceed with the launch, as business needs outweigh security concerns.
- BImplement compensating controls to mitigate the vulnerability until a permanent patch can be applied post-launch.
- CForce a delay in the launch until all legacy components are fully patched, regardless of business impact.
- DTransfer the risk by purchasing a comprehensive cyber insurance policy for the new platform.
Show answer & explanationAnswer & explanation
Correct answer: B. Implement compensating controls to mitigate the vulnerability until a permanent patch can be applied post-launch.
In situations where immediate remediation is not feasible due to business constraints, implementing compensating controls is the most appropriate risk management strategy. This allows the business to proceed while actively reducing the risk exposure until a full solution can be deployed, demonstrating alignment between security and business objectives.
Why the other options are wrong
- A. Accepting a high risk without mitigation is generally not an appropriate security management response, especially for a financial institution.
- C. Forcing a delay without exploring alternatives demonstrates a lack of business alignment and may not be feasible or strategic.
- D. Cyber insurance transfers financial risk but does not reduce the likelihood or impact of an actual security incident, which is the primary goal of risk management.
Compensating Controls
Alternative security measures that are put in place to satisfy the requirement of a security control that cannot be met due to technical or business constraints.
- Provides temporary or alternative protection.
- Used when primary controls are not feasible.
- Maintains an acceptable level of risk.
Memory trick: When the main shield is down, use a temporary one.