Project Management Professional (PMP)® Examination Content OutlineBusiness EnvironmentMedium
A project manager is leading a software development project. The organization regularly conducts internal security audits. A recent audit report highlighted a critical vulnerability in a third-party library currently being used in the project, which is not compliant with the organization's security policies. Remedying this vulnerability will require a significant refactor of a core module. What should the project manager do next?
- ADelegate the task of finding a compliant alternative to the development team without further oversight.
- BDocument the vulnerability as a risk and continue with the current plan, hoping it won't be exploited.
- CRaise a change request to address the non-compliance, including impact analysis and recommended solutions.
- DImmediately implement a workaround solution to avoid schedule delays, without formal approval.
Show answer & explanationAnswer & explanation
Correct answer: C. Raise a change request to address the non-compliance, including impact analysis and recommended solutions.
A critical vulnerability that causes non-compliance is a significant issue requiring formal management. The project manager must raise a change request, detailing the impact of the non-compliance and proposed solutions, to ensure the issue is formally reviewed, approved, and addressed within the project's change control process.
Why the other options are wrong
- A. While the development team will be involved, delegating without oversight or formal process risks an uncoordinated or inadequate solution to a critical problem.
- B. Ignoring a critical non-compliance issue and hoping for the best is irresponsible and exposes the organization to significant risk.
- D. Implementing significant changes or workarounds without formal approval bypasses change control and can lead to unintended consequences and project instability.
Internal Compliance Management
The process of ensuring a project adheres to an organization's internal policies, standards, and procedures, often identified through internal audits.
- Requires formal change control for deviations.
- Aims to maintain organizational standards and reduce internal risks.
- Involves proactive identification and remediation.
Memory trick: Internal audit finds a fault? Initiate a formal change, for sure!