ISC2 CISSP Practice Question
A global financial institution has several critical application servers running on an operating system that the vendor has announced will reach End of Support (EOS) in six months. The application is mission-critical and cannot be migrated to a newer platform for at least 18 months due to compatibility issues with other systems. What is the most appropriate approach for the organization to maintain security during this period?
Negotiate an Extended Support Agreement with the vendor
Air-gap the servers from external networks
Accept the risk since migration is planned
Add additional security controls and continue operations