Certified Information Security Manager (CISM)Information Security GovernanceMedium
An organization discovers that a critical financial system, developed years ago, does not fully comply with a recently enacted industry-specific data protection regulation. The CISO needs to present a remediation plan to senior management. Which of the following actions should the CISO prioritize to demonstrate due care and due diligence in this situation?
- AImmediately implement a temporary workaround to block all access to the system until full compliance is achieved.
- BFormally document the non-compliance and accept the associated risk, informing only the legal department.
- CInitiate a comprehensive gap analysis between the system's current state and the new regulatory requirements.
- DSchedule a meeting with the system's original developers to understand why the regulation was not considered.
Show answer & explanationAnswer & explanation
Correct answer: C. Initiate a comprehensive gap analysis between the system's current state and the new regulatory requirements.
Due care and due diligence in a non-compliance situation begin with a thorough understanding of the problem. A comprehensive gap analysis identifies specific areas of non-compliance and informs an effective remediation plan, demonstrating a responsible and systematic approach.
Why the other options are wrong
- A. Blocking all access without understanding the full impact or having a clear remediation path can cause significant business disruption and may not be necessary or practical.
- B. Accepting risk without a clear understanding of the gaps and a plan to address them does not demonstrate due care or due diligence, especially if only a limited group is informed.
- D. While understanding historical context can be useful, it's not the immediate priority for addressing current non-compliance. The focus should be on the present state and future remediation.
Due Care & Due Diligence
Due care refers to exercising the care that a reasonable and prudent person would exercise under the circumstances. Due diligence is the act of investigating and understanding the risks and requirements before taking action.
- Crucial for legal and ethical compliance.
- Due diligence precedes due care (investigate then act).
- Demonstrates responsible and systematic risk management.
Memory trick: When non-compliance hits, first analyze the gaps, then act with care.