A vulnerability analyst confirms a medium-severity web-server flaw cannot be patched for 90 days. The business owner accepts the risk. Which action best supports accountable vulnerability management?
Select an answer to reveal the explanation.
Short Explanation
Think of risk acceptance like a signed parking ticket: if you ignore it, it just sits there. Document the residual risk, compensating controls, and review date so someone can revisit the decision. That keeps the accepted risk visible instead of quietly forgotten.
Full Explanation
Risk acceptance is a governance decision, not a technical closure. When a vulnerability cannot be remediated in the desired timeframe, the analyst must communicate what remains exposed, what controls reduce likelihood or impact, and when the decision will be reevaluated. This creates an auditable record that aligns technical exposure with business tolerance and prevents the issue from disappearing after a scan. Suppressing a finding only removes it from reporting; it does not record residual risk, assign accountability, or schedule reassessment. A firewall change may be a compensating control, but recording it in a change ticket is not a complete risk acceptance artifact because it omits residual exposure, ownership, and review timing. Repeated scanning provides monitoring data, yet without a documented acceptance decision it leaves management unaware of tolerated exposure and may trigger repeated findings. Exam caveat: accepted risk is valid only when documented, communicated, and time-bound; otherwise it is an unmanaged vulnerability. Operational check: create a risk-acceptance ticket that links the CVE, asset owner, residual CVSS or business impact, compensating controls, approval, and next review date.