ISACA Certified Information Systems Auditor (CISA) ExamDomain 5: Protection of Information AssetsMedium
A CISA is auditing an organization's vulnerability management program. The CISA reviews the vulnerability scan reports and observes that while critical vulnerabilities are identified, the average time to remediate them is 90 days, significantly exceeding the organization's policy of 30 days for critical issues. Upon further investigation, the CISA finds that the remediation team is frequently delayed waiting for patch approvals and change management windows. What is the MOST appropriate recommendation for the CISA to make?
- AImplement a dedicated remediation team with more resources.
- BIncrease the frequency of vulnerability scanning to identify issues sooner.
- CStreamline the patch approval and change management processes.
- DRevise the organization's policy to align with the actual remediation time.
Show answer & explanationAnswer & explanation
Correct answer: C. Streamline the patch approval and change management processes.
The core problem identified is the delay caused by patch approvals and change management processes. Streamlining these processes will directly address the bottleneck preventing timely remediation and help the organization meet its policy objectives for critical vulnerabilities.
Why the other options are wrong
- A. More resources might help, but if the process itself is the bottleneck, additional staff might just sit idle waiting for approvals.
- B. Scanning frequency won't resolve the bottleneck in *remediation* once vulnerabilities are identified.
- D. Aligning the policy with current, inadequate performance is accepting the risk, not improving the security posture, and is generally not an appropriate audit recommendation.
Vulnerability Remediation Process Optimization
Improving the efficiency and speed of fixing identified security vulnerabilities by streamlining workflows, reducing bureaucratic delays, and enhancing coordination between teams.
- Focuses on reducing time-to-remediate (TTR).
- Involves optimizing patch management, change control, and approval processes.
- Aims to meet defined service level agreements (SLAs) or policies.
Memory trick: The fix is ready, but the approval traffic light is stuck on red.