ISC2 CISSP (Certified Information Systems Security Professional)Security Assessment and TestingMedium
During a security audit, an auditor discovers that critical system patches have not been applied within the mandated 30-day window, despite a clear organizational policy requiring it. The audit finding indicates a deficiency in which area?
- ASecurity policy compliance
- BSecurity control implementation
- CSecurity architecture design
- DSecurity control effectiveness
Show answer & explanationAnswer & explanation
Correct answer: A. Security policy compliance
The scenario explicitly states there is a 'clear organizational policy requiring it' and that the patches 'have not been applied within the mandated 30-day window'. This directly points to a failure to adhere to established policy, which is a compliance issue.
Why the other options are wrong
- B. Implementation refers to putting controls in place, but here the issue is ongoing adherence.
- C. Architecture design relates to the fundamental structure, not the execution of patching.
- D. Effectiveness relates to whether the control actually achieves its goal; here, the control (patching) wasn't even performed as required.
Security Policy Compliance
The act of adhering to an organization's internal security policies, standards, and procedures, as well as external regulations and legal requirements.
- Ensures alignment with organizational security posture
- Audits verify compliance status
- Non-compliance indicates a gap in security governance
Memory trick: Audit uncovers Policy breaks, Design flaws, or weak Controls.