712-50 Question 69
Single answerA newly appointed CISO at a regional healthcare provider reviews the latest internal audit and discovers several control gaps: privileged administrator accounts are shared by IT staff, quarterly access reviews have not been performed for 18 months, and critical patient-record servers are missing centralized log monitoring. The organization has a limited budget this fiscal year and cannot fund a major technology refresh. The board has asked for a practical remediation plan that reduces the most significant exposure quickly while demonstrating responsible use of funds. Which action should the CISO recommend FIRST?
- A
Implement a phased plan that immediately eliminates shared administrator accounts, enforces unique privileged IDs with MFA where feasible, restores periodic access reviews for high-risk systems, and enables centralized logging on critical servers using existing SIEM capacity before expanding further
- B
Purchase a new user and entity behavior analytics platform to detect misuse by privileged users, then defer access review and account cleanup until the platform is fully tuned
- C
Accept the risk temporarily because no confirmed breach has occurred, and focus the current budget on awareness training for all employees
- D
Conduct a full enterprise-wide control redesign project across all business units before changing any of the identified controls so that the final architecture is standardized
Show answer and explanation
Correct answer: A
Explanation
The best answer is the phased, risk-based remediation plan because it directly addresses the most significant exposures caused by ineffective or missing controls while remaining practical under budget constraints. From a governance and risk management perspective, the CISO should prioritize remediation based on impact, likelihood, and business criticality rather than pursue broad redesigns or expensive new tools first. Shared privileged accounts are a major exposure because they prevent individual accountability, weaken separation of duties, and hinder forensic investigation. Missing access reviews increase the risk of inappropriate, excessive, or lingering access. Lack of centralized logging on critical servers reduces detection and response capability.
This approach is consistent with widely accepted security and control practices. NIST SP 800-53 emphasizes account management, least privilege, audit logging, and review of accounts and privileges through controls such as AC-2, AC-6, AU-2, and AU-6. CIS Critical Security Controls also prioritize inventory and control of accounts, access control management, and audit log management. ISO/IEC 27001 and 27002 similarly stress access control, privileged access management, logging, and periodic review of user access rights. In a CCISO context, the key is not merely identifying weaknesses, but formulating a prioritized, cost-effective remediation plan that reduces material exposure quickly, uses existing capabilities where possible, and demonstrates sound executive judgment.
- A. Correct.
Correct. This option addresses the highest-risk and most immediate exposures with a practical, cost-conscious sequence. Shared privileged accounts undermine accountability and nonrepudiation, increase insider and external misuse risk, and complicate incident investigations. Restoring access reviews reduces the likelihood of excessive or orphaned access persisting on sensitive systems. Enabling centralized logging on critical servers improves detective capability and supports monitoring of privileged activity. Using existing SIEM capacity and applying controls first to high-risk systems reflects sound risk-based prioritization and cost-effective remediation.
- B. Incorrect.
Incorrect. While behavior analytics may add value, buying a new platform first is not the most practical or cost-effective initial step when foundational controls are missing. Analytics cannot compensate for weak identity governance, shared privileged credentials, or absent access reviews. This option reflects a common mistake of prioritizing advanced detection technology before fixing basic preventive and administrative controls.
- C. Incorrect.
Incorrect. Risk acceptance is inappropriate here because the identified gaps affect privileged access, access governance, and logging on critical patient-record systems, all of which present material operational, privacy, and compliance exposure. Awareness training is beneficial in general, but it does not directly remediate the specific control failures creating the current high-risk condition.
- D. Incorrect.
Incorrect. A full control redesign may eventually be useful, but delaying corrective action until a large transformation is planned leaves major exposures unaddressed. This option is less practical for a constrained budget and does not align with the board's request for timely risk reduction. Effective CISOs typically implement prioritized corrective actions quickly while planning longer-term improvements separately.