Project Management Professional (PMP)® Examination Content OutlineBusiness EnvironmentMedium

A project manager is leading a software development project. The organization regularly conducts internal security audits. A recent audit report highlighted a critical vulnerability in a third-party library currently being used in the project, which is not compliant with the organization's security policies. Remedying this vulnerability will require a significant refactor of a core module. What should the project manager do next?

  1. ADelegate the task of finding a compliant alternative to the development team without further oversight.
  2. BDocument the vulnerability as a risk and continue with the current plan, hoping it won't be exploited.
  3. CRaise a change request to address the non-compliance, including impact analysis and recommended solutions.
  4. DImmediately implement a workaround solution to avoid schedule delays, without formal approval.
Show answer & explanation

Correct answer: C. Raise a change request to address the non-compliance, including impact analysis and recommended solutions.

A critical vulnerability that causes non-compliance is a significant issue requiring formal management. The project manager must raise a change request, detailing the impact of the non-compliance and proposed solutions, to ensure the issue is formally reviewed, approved, and addressed within the project's change control process.

Why the other options are wrong

  • A. While the development team will be involved, delegating without oversight or formal process risks an uncoordinated or inadequate solution to a critical problem.
  • B. Ignoring a critical non-compliance issue and hoping for the best is irresponsible and exposes the organization to significant risk.
  • D. Implementing significant changes or workarounds without formal approval bypasses change control and can lead to unintended consequences and project instability.

Internal Compliance Management

The process of ensuring a project adheres to an organization's internal policies, standards, and procedures, often identified through internal audits.

  • Requires formal change control for deviations.
  • Aims to maintain organizational standards and reduce internal risks.
  • Involves proactive identification and remediation.

Memory trick: Internal audit finds a fault? Initiate a formal change, for sure!

More Business Environment questions