How Should Unpatched Systems Violating Policy Be Treated?
A situation where an organization has unpatched IT systems in violation of the patching policy should be treated as:
Community Votes
43% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Tests the distinction between technical control failures and strategic risk assessment, with the common trap being focusing on the operational breakdown instead of the executive-level risk impact.
This CISM question examines how organizations should classify unpatched systems that breach patching policies, with community consensus favoring an increased risk profile as the appropriate management response.
Option D (security control failure) is frequently selected because missing patches clearly indicate a broken safeguard, but CISM prioritizes treating policy deviations as elevated risk profiles that demand leadership intervention.
Community Discussion (4 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
In the CISM framework, management’s primary mandate is risk governance rather than technical compliance tracking. Unpatched systems introduce exploitable weaknesses that, when exposed to active threats, directly elevate the organization’s overall risk posture. Treating this violation as an increased risk profile ensures that executive stakeholders recognize the business impact and allocate necessary remediation resources. Leadership must prioritize risk mitigation over mere policy enforcement.Why the Other Options Are Wrong
Option A misclassifies the issue because patching gaps do not alter the external threat actors’ intentions or capabilities. Option B describes the operational process breakdown but fails to capture the strategic consequence that leadership must address. Option D correctly identifies a control breakdown, yet ISACA expects candidates to pivot from technical symptoms to the broader risk implications that drive business decisions. Focusing solely on controls ignores the financial and reputational exposure.Community Comment Notes
Comment [1] argues for option D, emphasizing that policy violations inherently represent control failures, though this overlooks the managerial lens required by CISM. Comments [2] and [4] strongly support option C, noting that unpatched infrastructure expands the environmental risk exposure. The vote split highlights a classic certification debate between operational compliance and strategic risk management. Exam candidates should weigh these perspectives against official ISACA guidance.Official Reference
Exam Strategy
Always shift from a technical operator’s mindset to a manager’s perspective when tackling CISM scenarios. Ask yourself what executive leadership needs to see to justify budget and prioritization, as policy deviations are consistently framed as business risks requiring strategic oversight.
Frequently Asked Questions
Why is option D (security control failure) incorrect for unpatched systems?
While unpatched systems do indicate a control failure, CISM requires managers to treat the operational gap as an elevated business risk requiring executive action.
How does a vulnerability differ from an increased risk profile in CISM exams?
A vulnerability is a technical weakness like missing patches, whereas risk combines that weakness with threat likelihood and potential business impact.
Related Analysis
Practice All CISM Questions
Access 400 questions with complete answers and detailed explanations.
View Full CISM Practice Test →