情報セキュリティ マネージャーは、リスク所有者がプロセスの効率性を向上させるために、主要なコントロールをより弱い代替コントロールに置き換える例外を承認したことを知ります。次のうち、最も懸念すべきことはどれですか。
正解:A
Replacing key controls with weaker compensating controls may introduce new vulnerabilities or increase the likelihood or impact of existing threats, thus raising the risk levels beyond the acceptable limits defined by the risk appetite and tolerance of the organization. This may expose the organization to unacceptable losses or damages, such as financial, reputational, legal, or operational. Therefore, the information security manager should be most concerned about the potential elevation of risk levels and ensure that the risk owner is aware of the consequences and accountable for the decision.
References = CISM Review Manual, 16th Edition, Chapter 2: Information Risk Management, Section: Risk Treatment, page 941.