During a quarterly security review, a financial services company discovers that a legacy payment application cannot support the mandated full-disk encryption control without causing system instability. To maintain service availability, the CISO invokes the organization's documented security exception handling process. Which activity BEST captures the primary purpose of this process?
Compile audit evidence to address compliance findings from external regulators
Trigger the incident response plan to contain and eradicate the vulnerability
Record unusual events detected by the vulnerability scanner for root-cause analysis
Document and track the deviation from policy, assess risk, and obtain approval with compensating controls
A security exception handling process exists to formally acknowledge when a control cannot be implemented as prescribed, assess and document the associated risk, identify and track compensating controls, obtain formal approval or risk acceptance from the appropriate authority, and establish review or remediation deadlines. It is not designed to log unusual events, coordinate incident response activities, or compile routine audit evidence-those functions are handled by other operational and compliance processes.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What are compensating controls in the context of security exception handling?
Open an interactive chat with Bash
Who is typically responsible for approving security exceptions?
Open an interactive chat with Bash
How does the security exception handling process support risk management?
Open an interactive chat with Bash
ISC2 CISSP
Security Assessment and Testing
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .