How Should Unpatched Systems Violating Policy Be Treated?

Risk Management
Answer Correct answer: C — Treat unpatched systems violating the patching policy as an increased risk profile to prioritize executive remediation and resource allocation.

A situation where an organization has unpatched IT systems in violation of the patching policy should be treated as:

  1. an increased threat profile.
  2. a vulnerability management failure.
  3. an increased risk profile. Correct Answer
  4. a security control failure.

Community Votes

C
43%
B
29%
D
29%

43% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Tests the distinction between technical control failures and strategic risk assessment, with the common trap being focusing on the operational breakdown instead of the executive-level risk impact.

This CISM question examines how organizations should classify unpatched systems that breach patching policies, with community consensus favoring an increased risk profile as the appropriate management response.

Option D (security control failure) is frequently selected because missing patches clearly indicate a broken safeguard, but CISM prioritizes treating policy deviations as elevated risk profiles that demand leadership intervention.

Community Discussion (4 comments)

SHERLOCKAWS 👍 2 Selected: D
D seems best answer here because the patching policy is a control >> It was not followed or enforced >> so the control failed. Yes yes, the risk has increased. But this is a result of the problem, not the core issue itself.
oluchecpoint 👍 2 Selected: C
C. an increased risk profile An unpatched server increases the risk in the environment
bronay 👍 2 Selected: B
B. Vulnerability management failure
ssdny 👍 1 Selected: C
Rist Profile = type and amount of risk

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

In the CISM framework, management’s primary mandate is risk governance rather than technical compliance tracking. Unpatched systems introduce exploitable weaknesses that, when exposed to active threats, directly elevate the organization’s overall risk posture. Treating this violation as an increased risk profile ensures that executive stakeholders recognize the business impact and allocate necessary remediation resources. Leadership must prioritize risk mitigation over mere policy enforcement.

Why the Other Options Are Wrong

Option A misclassifies the issue because patching gaps do not alter the external threat actors’ intentions or capabilities. Option B describes the operational process breakdown but fails to capture the strategic consequence that leadership must address. Option D correctly identifies a control breakdown, yet ISACA expects candidates to pivot from technical symptoms to the broader risk implications that drive business decisions. Focusing solely on controls ignores the financial and reputational exposure.

Community Comment Notes

Comment [1] argues for option D, emphasizing that policy violations inherently represent control failures, though this overlooks the managerial lens required by CISM. Comments [2] and [4] strongly support option C, noting that unpatched infrastructure expands the environmental risk exposure. The vote split highlights a classic certification debate between operational compliance and strategic risk management. Exam candidates should weigh these perspectives against official ISACA guidance.

Official Reference

Exam Strategy

Always shift from a technical operator’s mindset to a manager’s perspective when tackling CISM scenarios. Ask yourself what executive leadership needs to see to justify budget and prioritization, as policy deviations are consistently framed as business risks requiring strategic oversight.

Frequently Asked Questions

Why is option D (security control failure) incorrect for unpatched systems?

While unpatched systems do indicate a control failure, CISM requires managers to treat the operational gap as an elevated business risk requiring executive action.

How does a vulnerability differ from an increased risk profile in CISM exams?

A vulnerability is a technical weakness like missing patches, whereas risk combines that weakness with threat likelihood and potential business impact.

Related Analysis

Practice All CISM Questions

Access 400 questions with complete answers and detailed explanations.

View Full CISM Practice Test →

← Back to CISM Study Guide