Topic 6 DQ 1
docx
keyboard_arrow_up
School
Grand Canyon University *
*We aren’t endorsed by this school
Course
CYB-515
Subject
Information Systems
Date
Dec 6, 2023
Type
docx
Pages
1
Uploaded by jeffermine
Exception management is identifying and handling cases that deviate from the normal behavior in a
business or technical context. It involves finding the root cause of the exception, resolving it, and
preventing it from happening again. (
Exception Management | Infosec
, n.d.)
Exception management is required because existing policies, procedures, or frameworks cannot
anticipate or control every situation. Sometimes, some unforeseen circumstances or challenges require
special attention or intervention. For example, a security team may need to approve an exception for a
legacy application that cannot be upgraded to the latest version due to dependencies or compatibility
issues.
However, exception management is also risky if improperly used by technical managers. It can lead to
inconsistency, inefficiency, or insecurity in the system or process. If exceptions are not documented,
tracked, or appropriately closed, they can create loopholes or vulnerabilities that malicious actors can
exploit. For example, suppose a technical manager grants an exception for a user to access a restricted
resource without verifying the user's identity or authorization. In that case, it can compromise the
confidentiality or integrity of the data.
A real-world example of exception management is the case of the Boeing 737 Max, which was grounded
worldwide after two fatal crashes in 2018 and 2019. The crashes were caused by a software flaw in the
Maneuvering Characteristics Augmentation System (MCAS), designed to prevent the aircraft from
stalling. However, the MCAS relied on a single sensor to measure the angle of attack. If the sensor
malfunctioned, the MCAS would repeatedly push the plane's nose down, overriding the pilots' inputs.
The MCAS was an exception to the standard flight control system, and it was not adequately tested,
communicated, or mitigated by the technical managers at Boeing. As a result, the MCAS caused a
catastrophic failure that cost hundreds of lives and billions of dollars. (German, 2021)
References
Exception management | Infosec
. (n.d.).
https://resources.infosecinstitute.com/topics/management-
compliance-auditing/exception-management/
German, K. (2021, June 19). 2 years after being grounded, the Boeing 737 Max is flying again.
CNET
.
https://www.cnet.com/tech/tech-industry/boeing-737-max-8-all-about-the-aircraft-flight-ban-and-
investigations/
Discover more documents: Sign up today!
Unlock a world of knowledge! Explore tailored content for a richer learning experience. Here's what you'll get:
- Access to all documents
- Unlimited textbook solutions
- 24/7 expert homework help