組織の重要な IT システムの 1 つにパッチを適用することができません。パッチを適用すると、重要なビジネス アプリケーションの機能に支障をきたすためです。リスク管理担当者にとって最も適切な推奨事項は次のうちどれでしょうか。
正解:A
The risk practitioner's best recommendation when one of an organization's key IT systems cannot be patched because the patches interfere with critical business application functionalities is to identify additional mitigating controls, as they may reduce the likelihood or impact of the vulnerabilities being exploited, and align the residual risk with the risk tolerance and appetite of the organization. The other options are not the best recommendations, as they may not address the risk adequately, or may introduce unacceptable consequences, such as disrupting the businessoperations, changing the risk strategy, or accepting excessive risk. References = CRISC Review Manual, 7th Edition, page 111.