A security manager is leading a risk assessment for the organization. The team identifies a legacy application that contains a known critical vulnerability. The vendor has discontinued support and no patch is available. The manager calculates that the annualized loss expectancy (ALE) for exploiting this vulnerability is $50,000. Implementing a third-party web application firewall (WAF) as a compensating control would cost $80,000 per year. The organization's leadership decides that accepting the risk is the most cost-effective approach. Which of the following documents should the security manager update to formally record this risk acceptance decision and obtain the necessary sign-off?
Correct. The risk register is used to track identified risks, their characteristics, and the chosen treatment. Updating it with the acceptance decision, rationale, and approval is essential for risk governance.
Why this answer
The risk register is the correct document to update because it formally tracks identified risks, their assessed impact, and the chosen risk response (acceptance). Recording the decision to accept the $50,000 ALE risk and obtaining sign-off ensures auditability and accountability, which is a key requirement in risk management frameworks like NIST SP 800-37.
Exam trap
The trap here is that candidates confuse the risk register with the BIA, mistakenly thinking the BIA is used to document risk acceptance decisions, when in fact the BIA only quantifies impact and does not track risk treatment or sign-off.
Why the other options are wrong
A BIA documents the impact of disruptions on business operations, not the formal acceptance of specific risks. The risk acceptance decision should be recorded in the risk register, which tracks identified risks, their assessments, and management decisions including acceptance and sign-off.
A security baseline configuration document defines secure settings for systems, not risk acceptance decisions. The question asks for recording a formal risk acceptance decision with sign-off, which is a function of the risk register.
The incident response plan outlines procedures for detecting, responding to, and recovering from security incidents, not for formally documenting risk acceptance decisions or obtaining sign-off on risk treatment.