Study. uk . com
  1. Home
  2. All questions
  3. Question 429

CISSP study material · question 429 of 500

A production line controller cannot be patched without vendor recertification that will take two years. Which approach does NIST SP 800-40 Rev. 4 prescribe? Choose two.

  1. Accept the risk formally and take no compensating action until the vendor delivers.
  2. Apply layered long-term mitigation such as micro-segmentation or a software-defined perimeter to isolate the asset.
  3. Remove the asset from the vulnerability management programme, since it cannot be remediated.
  4. Have security architects review and approve the mitigation methods for each maintenance group in advance.
Show the answer

Answer: B. Apply layered long-term mitigation such as micro-segmentation or a software-defined perimeter to isolate the asset.
D. Have security architects review and approve the mitigation methods for each maintenance group in advance.

SP 800-40 expects multiple long-term mitigation methods for unpatchable assets, reviewed and analysed in advance by security architects for each maintenance group, citing isolation approaches such as micro-segmentation.

Source: NIST SP 800-40 Rev. 4 (NIST) — SP 800-40 Rev. 4 > 3.5.4 Maintenance Plans for Scenario 4, Unpatchable Assets

Challenge yourself on this topic → Study as cards