情報セキュリティ管理者は、プロセスの効率を改善するために主要な統制をより弱い補完的な統制に置き換える例外をリスク所有者が承認したことを知ります。次のうち、最も懸念すべきことはどれですか?
正解:A
Explanation
Replacing key controls with weaker compensating controls may introduce new vulnerabilities or increase the likelihood or impact of existing threats, thus raising the risk levels beyond the acceptable limits defined by the risk appetite and tolerance of the organization. This may expose the organization to unacceptable losses or damages, such as financial, reputational, legal, or operational. Therefore, the information security manager should be most concerned about the potential elevation of risk levels and ensure that the risk owner is aware of the consequences and accountable for the decision.
References = CISM Review Manual, 16th Edition, Chapter 2: Information Risk Management, Section: Risk Treatment, page 941.