QuestionQ207

Information Security Program

After password standards have been updated, an information security manager is notified by several application administrators that the applications they support cannot enforce those standards. What should be the information security manager's FIRST course of action?

  • A evaluate the cost of replacing the applications.
  • B reevaluate the standards.
  • C determine the potential impact.
  • D implement compensating controls.
Explanation

A risk-based response begins by determining the potential business and security impact of applications that cannot enforce the updated password standards. That assessment establishes the severity and priority of the gap and informs whether compensating controls, application replacement, or another treatment is appropriate.

Community Discussion

No comments yet. Be the first to start the discussion!