CRISC Certified in Risk and Information Systems ControlGovernanceHard

A financial services organization is developing a new mobile banking application. The project team is pressured to meet aggressive launch deadlines, and some developers are proposing to bypass certain security testing phases to accelerate the release. The Chief Information Security Officer (CISO) is aware of the situation. Which of the following is the MOST effective action for the CISO to take to maintain professional ethics and organizational risk posture?

  1. AEscalate the issue to executive management, clearly outlining the risks associated with bypassing security testing and potential ethical breaches.
  2. BAuthorize a reduced scope of security testing, provided the development team commits to addressing all findings post-launch.
  3. CRequire the development team to sign a waiver acknowledging the risks of reduced testing, thereby shifting accountability.
  4. DImplement a 'bug bounty' program post-launch to incentivize external researchers to find vulnerabilities that might have been missed.
Show answer & explanation

Correct answer: A. Escalate the issue to executive management, clearly outlining the risks associated with bypassing security testing and potential ethical breaches.

Bypassing security testing phases for aggressive deadlines is a significant risk and an ethical breach. The CISO's professional ethical duty involves protecting the organization, and this situation warrants immediate escalation to executive management to ensure they are fully aware of the risks and can make an informed decision, rather than implicitly accepting the risk or attempting to shift accountability.

Why the other options are wrong

  • B. Authorizing reduced testing is an acceptance of increased risk and a potential ethical compromise, especially if findings are addressed post-launch.
  • C. Shifting accountability through a waiver does not mitigate the risk or absolve the CISO of their ethical responsibility to protect the organization.
  • D. A bug bounty program is a supplementary measure and does not replace thorough pre-launch security testing or address the immediate ethical concern.

Ethical Escalation

The professional duty to report significant risks, ethical breaches, or non-compliance to appropriate higher authorities within an organization when direct resolution is not possible or sufficient.

  • Protects the organization from undue risk.
  • Upholds professional integrity and ethics.
  • Ensures informed decision-making at appropriate levels.

Memory trick: When the ethical alarm blares, the CISO's duty is to signal UP.

More Governance questions