nerdexam
CompTIA

CAS-002 · Question #197

A team of security engineers has applied regulatory and corporate guidance to the design of a corporate network. The engineers have generated an SRTM based on their work and a thorough analysis of…

The correct answer is D. To allow certifiers to verify the network meets applicable security requirements. An SRTM traces security requirements to implemented controls, providing certifiers with the evidence needed to verify that all applicable security requirements are satisfied.

Enterprise Security

Question

A team of security engineers has applied regulatory and corporate guidance to the design of a corporate network. The engineers have generated an SRTM based on their work and a thorough analysis of the complete set of functional and performance requirements in the network specification. Which of the following BEST describes the purpose of an SRTM in this scenario?

Options

  • ATo ensure the security of the network is documented prior to customer delivery
  • BTo document the source of all functional requirements applicable to the network
  • CTo facilitate the creation of performance testing metrics and test plans
  • DTo allow certifiers to verify the network meets applicable security requirements

How the community answered

(25 responses)
  • A
    4% (1)
  • B
    4% (1)
  • C
    12% (3)
  • D
    80% (20)

Why each option

An SRTM traces security requirements to implemented controls, providing certifiers with the evidence needed to verify that all applicable security requirements are satisfied.

ATo ensure the security of the network is documented prior to customer delivery

Documentation for customer delivery is a project management deliverable and does not describe the certification and accreditation-focused purpose of an SRTM.

BTo document the source of all functional requirements applicable to the network

Documenting the source of all functional requirements is the role of a general requirements traceability matrix (RTM); an SRTM specifically traces security requirements to controls, not the origin of all functional requirements.

CTo facilitate the creation of performance testing metrics and test plans

Performance testing metrics and test plans are derived from performance requirements and test planning documents, not from a security requirements traceability matrix.

DTo allow certifiers to verify the network meets applicable security requirementsCorrect

A Security Requirements Traceability Matrix (SRTM) maps each regulatory and corporate security requirement to the specific controls implemented in the system, enabling certifiers and auditors to verify requirement coverage and grant authorization to operate - this traceability function is its core purpose within the Risk Management Framework process.

Concept tested: Security Requirements Traceability Matrix purpose in certification

Source: https://csrc.nist.gov/publications/detail/sp/800-37/rev-2/final

Topics

#SRTM#security requirements traceability#security certification#network compliance

Community Discussion

No community discussion yet for this question.

Full CAS-002 Practice