ISC2 CISSP (Certified Information Systems Security Professional)Security Assessment and TestingMedium

During a security audit, an auditor discovers that critical system patches have not been applied within the mandated 30-day window, despite a clear organizational policy requiring it. The audit finding indicates a deficiency in which area?

  1. ASecurity policy compliance
  2. BSecurity control implementation
  3. CSecurity architecture design
  4. DSecurity control effectiveness
Show answer & explanation

Correct answer: A. Security policy compliance

The scenario explicitly states there is a 'clear organizational policy requiring it' and that the patches 'have not been applied within the mandated 30-day window'. This directly points to a failure to adhere to established policy, which is a compliance issue.

Why the other options are wrong

  • B. Implementation refers to putting controls in place, but here the issue is ongoing adherence.
  • C. Architecture design relates to the fundamental structure, not the execution of patching.
  • D. Effectiveness relates to whether the control actually achieves its goal; here, the control (patching) wasn't even performed as required.

Security Policy Compliance

The act of adhering to an organization's internal security policies, standards, and procedures, as well as external regulations and legal requirements.

  • Ensures alignment with organizational security posture
  • Audits verify compliance status
  • Non-compliance indicates a gap in security governance

Memory trick: Audit uncovers Policy breaks, Design flaws, or weak Controls.

More Security Assessment and Testing questions