During the compliance determination phase, you discover that a legacy application lacks multi-factor authentication (MFA) but is isolated within a physically secured enclave. Which action should you take to document this in the Security Assessment Report (SAR)?
Trap 1: Force an upgrade to the application
This is a remediation step, not an assessment step.
Trap 2: Immediately revoke the Authorization to Operate (ATO)
Risk assessment must occur before revoking an ATO.
Trap 3: Mark the control as 'Not Applicable'
The control is applicable; it is just unimplemented.
- A
Force an upgrade to the application
Why wrong: This is a remediation step, not an assessment step.
- B
Document the compensating control and assess its effectiveness
Compensating controls are valid methods to meet security requirements.
- C
Immediately revoke the Authorization to Operate (ATO)
Why wrong: Risk assessment must occur before revoking an ATO.
- D
Mark the control as 'Not Applicable'
Why wrong: The control is applicable; it is just unimplemented.