A public-health clinic still runs FDA-cleared diagnostic devices that the vendor will not patch this year. Vulnerability scans keep flagging them. What is the most appropriate security-operations response?
Select an answer to reveal the explanation.
Short Explanation
You can’t always slam “patch now” on a clinical box. Write the exception, fence it off the main network, watch it, and lock who can touch it—until a real fix shows up.
Full Explanation
When systems cannot be patched promptly—common with specialized medical devices—operations manage residual risk through formal exceptions and compensating controls such as segmentation or isolation, enhanced monitoring, and strict access limits. Ignoring findings or forcing unvalidated upgrades can harm safety and compliance. Guest-network exposure increases attack surface rather than containing it. Documented risk acceptance with mitigations keeps clinical function and security governance aligned.