ビジネスでは、アプリケーションのレガシー バージョンを運用する必要がありますが、アプリケーションにパッチを適用できません。ビジネスへのリスクの露出を制限するために、レガシー アプリケーションの前面にファイアウォールが実装されています。どのリスク処理オプションが適用されていますか?
正解:A
Mitigate is the risk treatment option that has been applied by implementing a firewall in front of the legacy application because it helps to reduce the impact or probability of a risk. Mitigate is a process of taking actions to lessen the negative effects of a risk, such as implementing security controls, policies, or procedures.
A firewall is a security device that monitors and filters the network traffic between the legacy application and the external network, blocking or allowing packets based on predefined rules. A firewall helps to mitigate the risk of unauthorized access, exploitation, or attack on the legacy application that cannot be patched.
Therefore, mitigate is the correct answer.
References:
https://simplicable.com/risk/risk-treatment
https://resources.infosecinstitute.com/topic/risk-treatment-options-planning-prevention/
https://www.enisa.europa.eu/topics/risk-management/current-risk/risk-management-inventory/rm-process/risk- treatment.