Certified Information Security Manager (CISM)Information Security GovernanceMedium

An organization discovers that a critical financial system, developed years ago, does not fully comply with a recently enacted industry-specific data protection regulation. The CISO needs to present a remediation plan to senior management. Which of the following actions should the CISO prioritize to demonstrate due care and due diligence in this situation?

  1. AImmediately implement a temporary workaround to block all access to the system until full compliance is achieved.
  2. BFormally document the non-compliance and accept the associated risk, informing only the legal department.
  3. CInitiate a comprehensive gap analysis between the system's current state and the new regulatory requirements.
  4. DSchedule a meeting with the system's original developers to understand why the regulation was not considered.
Show answer & explanation

Correct answer: C. Initiate a comprehensive gap analysis between the system's current state and the new regulatory requirements.

Due care and due diligence in a non-compliance situation begin with a thorough understanding of the problem. A comprehensive gap analysis identifies specific areas of non-compliance and informs an effective remediation plan, demonstrating a responsible and systematic approach.

Why the other options are wrong

  • A. Blocking all access without understanding the full impact or having a clear remediation path can cause significant business disruption and may not be necessary or practical.
  • B. Accepting risk without a clear understanding of the gaps and a plan to address them does not demonstrate due care or due diligence, especially if only a limited group is informed.
  • D. While understanding historical context can be useful, it's not the immediate priority for addressing current non-compliance. The focus should be on the present state and future remediation.

Due Care & Due Diligence

Due care refers to exercising the care that a reasonable and prudent person would exercise under the circumstances. Due diligence is the act of investigating and understanding the risks and requirements before taking action.

  • Crucial for legal and ethical compliance.
  • Due diligence precedes due care (investigate then act).
  • Demonstrates responsible and systematic risk management.

Memory trick: When non-compliance hits, first analyze the gaps, then act with care.

More Information Security Governance questions