During an asset inventory review, a security analyst discovers that several pharmacy point-of-sale terminals are running an operating system version that reached end-of-life two years ago. The vendor no longer issues patches. Which action should the security manager recommend FIRST?
- AEscalate the finding to the business owner with a risk assessment so that an informed decision can be made about replacement, compensating controls, or formal acceptance. Correct
- BReimage the terminals with a community-supported fork of the same operating system so that patches continue to flow from independent maintainers.
- CRemove the terminals from the network at the next maintenance window to eliminate the unpatched exposure on the production segment.
- DDocument the gap in the next quarterly asset report and continue routine vulnerability scanning until the issue is naturally addressed.
Why A is correct: The CISSP-favoured move is to surface the risk to the owner with enough evidence to choose between remediation, mitigation, and acceptance; the security manager facilitates the risk decision rather than acting unilaterally.
Why B is wrong: Community forks may introduce unsupported components into a regulated environment and rarely satisfy compliance auditors looking for a vendor-supported baseline; this is a technical workaround that bypasses the risk decision that needs to be made first.
Why C is wrong: Disconnecting pharmacy terminals affects patient care and revenue, and the decision belongs to the business owner once they understand the risk; the security manager does not own that trade-off and should not pre-empt it.
Why D is wrong: Logging the finding without escalation leaves an unpatched, end-of-life system in production indefinitely; passive monitoring is not a treatment, and routine reporting is not the same as a formal risk decision.