ISC2 CISSP (Certified Information Systems Security Professional)Security Assessment and TestingHard
A security auditor is performing a review of an organization's cloud environment. The auditor discovers that several critical data storage buckets are publicly accessible and contain sensitive customer information. The organization claims they were unaware of this configuration setting. This finding indicates a significant failure in which aspect of security assessment and testing?
- ASecurity Policy Enforcement
- BVulnerability Management Program
- CRisk Acceptance Process
- DContinuous Monitoring
Show answer & explanationAnswer & explanation
Correct answer: D. Continuous Monitoring
The discovery of publicly accessible sensitive data storage that the organization was unaware of points to a failure in continuous monitoring. A robust continuous monitoring program would regularly scan and assess cloud configurations and data exposure, alerting the organization to such critical misconfigurations before an auditor finds them.
Why the other options are wrong
- A. Security policy enforcement is about ensuring policies are followed, but if the organization is unaware of the misconfiguration, the failure is in detection, which falls under monitoring.
- B. While a vulnerability management program identifies weaknesses, continuous monitoring is specifically about *ongoing* review of the environment to detect changes and misconfigurations.
- C. Risk acceptance implies a conscious decision to accept a known risk. Here, the organization was 'unaware', indicating a failure in identifying the risk, not accepting it.
Continuous Monitoring
The ongoing, real-time or near real-time assessment of an organization's security posture to identify vulnerabilities, threats, and compliance deviations.
- Detects changes in configuration and security state.
- Crucial for dynamic environments like cloud.
- Involves automated tools and regular reviews.
Memory trick: ASSESSMENT STRATEGIES include MONITORING for ongoing health, VULNERABILITY scans, and POLICY enforcement.