CISSP - Asset Security - Section 2.5

Ensure appropriate asset retention covering end-of-life (EOL) and end-of-support (EOS).

Define retention policies that govern how long assets are kept in relation to legal, regulatory, and business requirements, including legal hold obligations that override standard schedules. Recognise the security and compliance risks created by retaining end-of-life (EOL) or end-of-support (EOS) assets beyond their supported lifespan.

retention policyend-of-lifeend-of-supportlegal hold

Practice question for this objective

Free sampleAsset Securityeasy

During an asset inventory review, a security analyst discovers that several pharmacy point-of-sale terminals are running an operating system version that reached end-of-life two years ago. The vendor no longer issues patches. Which action should the security manager recommend FIRST?

  • AEscalate the finding to the business owner with a risk assessment so that an informed decision can be made about replacement, compensating controls, or formal acceptance. Correct
  • BReimage the terminals with a community-supported fork of the same operating system so that patches continue to flow from independent maintainers.
  • CRemove the terminals from the network at the next maintenance window to eliminate the unpatched exposure on the production segment.
  • DDocument the gap in the next quarterly asset report and continue routine vulnerability scanning until the issue is naturally addressed.
When an asset has passed end-of-life, the security manager's first step is escalation to the business owner with a risk assessment, not unilateral technical action. Assets past end-of-life no longer receive vendor patches, so vulnerabilities accumulate without remediation. CISSP positions security as an advisor to the business: the manager translates the technical reality into a risk decision the owner can take, choosing between replacement, compensating controls such as network isolation, or documented risk acceptance. Acting unilaterally, whether by removing the system or applying an unsupported fork, bypasses that governance step.

Why A is correct: The CISSP-favoured move is to surface the risk to the owner with enough evidence to choose between remediation, mitigation, and acceptance; the security manager facilitates the risk decision rather than acting unilaterally.

Why B is wrong: Community forks may introduce unsupported components into a regulated environment and rarely satisfy compliance auditors looking for a vendor-supported baseline; this is a technical workaround that bypasses the risk decision that needs to be made first.

Why C is wrong: Disconnecting pharmacy terminals affects patient care and revenue, and the decision belongs to the business owner once they understand the risk; the security manager does not own that trade-off and should not pre-empt it.

Why D is wrong: Logging the finding without escalation leaves an unpatched, end-of-life system in production indefinitely; passive monitoring is not a treatment, and routine reporting is not the same as a formal risk decision.

See more CISSP practice questions, answers explained.

More in this domain

Back to all Asset Security objectives, or the CISSP cert hub.

Examworthy is not affiliated with or endorsed by (ISC)2. Original, blueprint-aligned practice material only.