A penetration test report for a regional bank lists 142 findings spanning critical, high, medium, and low severities across customer-facing and internal systems. The CISO must brief the executive risk committee in two days. Which approach should the CISO take FIRST when preparing the remediation roadmap for that briefing?
- ASort all findings by CVSS score and instruct asset owners to remediate every critical and high in the next sprint cycle.
- BForward the raw report to each system owner and ask them to self-rank findings on their own assets before the briefing.
- CMap each finding to the affected business process and asset criticality, then prioritise based on residual risk to the institution rather than raw severity alone. Correct
- DGroup findings by the technical control family that failed and present the briefing as a control maturity gap analysis only.
Why A is wrong: Pure CVSS sorting ignores business context, exploitability in the bank's environment, and existing compensating controls, so it produces a technically defensible but risk-blind queue that the committee cannot reasonably approve.
Why B is wrong: Delegating triage to system owners with no normalised risk framework produces inconsistent rankings, gaps where owners under-rate their own systems, and a roadmap the CISO cannot defend to the committee as a coherent view.
Why C is correct: CISSP-aligned remediation analysis combines technical severity with asset value, threat exposure, and existing controls so the committee approves remediation based on residual business risk, which is the manager-level lens the exam rewards.
Why D is wrong: A control maturity view is useful later for programme planning but it abstracts away the time-sensitive exploitable findings the committee must decide on, so it is a secondary output, not the first remediation step after a penetration test.