ISC2 Certified Secure Software Lifecycle Professional (CSSLP) Practice Question
A DevSecOps team discovers a moderate vulnerability in a third-party library two weeks before the planned production release. A compensating control limits the likelihood of exploitation, and the product owner decides the fix can wait until the next sprint. To keep the release on schedule and proceed toward an authorization to operate, what should the security lead do next to formally capture this decision for the authorizing official's review?
Create or update a Plan of Action and Milestones (POA&M) entry detailing the vulnerability, compensating controls, impact, and planned fix date.
Submit a standard change request ticket to defer patching until the next planned release.
Draft a risk acceptance (exception) memorandum and obtain the business owner's written sign-off.
Amend the service-level agreement to reference the outstanding vulnerability and proceed with deployment.
Under the Risk Management Framework, any vulnerability that will not be remediated before deployment must be entered into a Plan of Action and Milestones (POA&M). The POA&M records the vulnerability details, compensating controls, potential impact, and the planned mitigation schedule. It is included in the authorization package so the authorizing official can decide whether to accept the residual risk. Drafting a separate risk-acceptance memorandum comes later, after the AO reviews the POA&M and chooses to accept the risk. A standard change ticket or an SLA update do not meet the formal documentation requirements for residual-risk acceptance.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is a Plan of Action and Milestones (POA&M)?
Open an interactive chat with Bash
What are compensating controls, and how do they mitigate risk?
Open an interactive chat with Bash
What role does the authorizing official (AO) play in risk acceptance?
Open an interactive chat with Bash
What is the Plan of Action and Milestones (POA&M)?
Open an interactive chat with Bash
What is a compensating control?
Open an interactive chat with Bash
What does an authorizing official (AO) do in the RMF process?
Open an interactive chat with Bash
ISC2 Certified Secure Software Lifecycle Professional (CSSLP)