A serious vulnerability was detected in a business application that can be exploited by external attackers to compromise the system. What is the information security manager’s BEST course of action?
A.
Ask the business application owner to apply the fix immediately
The best course of action is to implement temporary remediation (B) to reduce exposure while a permanent fix is planned and approved. CISM emphasizes balancing risk reduction with business continuity. Immediate shutdown (C) or unilateral action (A) may disrupt business operations without proper authorization. Reporting the risk (D) is necessary but insufficient on its own. Temporary controls, such as access restrictions or additional monitoring, reduce risk while enabling informed decision-making by the business owner.
Chosen Answer:
This is a voting comment (?). You can switch to a simple comment. It is better to Upvote an existing comment if you don't have anything to add.
Submit