You are the chief information security officer (CISO), and due to a government shutdown and other factors, your desktop team is unable to migrate to the latest version of Windows as you initially planned. You know that your current version of Windows support will expire in just two weeks, and your agency will be vulnerable to all types of malware if you continue operating on it after the end of support deadline.
Using the information from the NIST framework readings, answer the following questions. How would you handle this risk? Would you accept, reject, transfer, or mitigate it? How did you come to that decision?
As the Chief Information Security Officer (CISO), I would handle the risk of operating on an unsupported version of Windows by mitigating it. This means that I would take steps to reduce the likelihood and impact of a security breach, while still allowing the agency to continue operating.
I came to this decision after considering the following factors:
I considered the other options, but I rejected them for the following reasons:
Mitigation Strategies
There are a number of mitigation strategies that I could implement to reduce the risk of operating on an unsupported version of Windows. These strategies could include:
Conclusion
Operating on an unsupported version of Windows is a serious security risk. However, there are a number of mitigation strategies that can be implemented to reduce the risk. By carefully considering the factors involved, I determined that the best way to handle the risk in this situation was to mitigate it.