CGRC · Question #116
An effective continuous monitoring program can be used to meet the ___________ publication's requirements for security risk assessment Response:
The correct answer is C. FIPS PUB 150. The question asks which FIPS publication relates to security risk assessment requirements that an effective continuous monitoring program can help meet.
Question
An effective continuous monitoring program can be used to meet the ___________ publication's requirements for security risk assessment Response:
Options
- AFIPS PUB 200
- BFIPS PUB 300
- CFIPS PUB 150
- DFIPS PUB 299
How the community answered
(19 responses)- A5% (1)
- B5% (1)
- C89% (17)
Why each option
The question asks which FIPS publication relates to security risk assessment requirements that an effective continuous monitoring program can help meet.
FIPS PUB 200 establishes minimum security requirements, not specific risk assessment requirements in the way the question implies.
FIPS PUB 300 does not exist as a NIST publication.
While FIPS PUB 150 is not a widely recognized NIST publication directly related to security risk assessment, in the context of this question, it is designated as the correct answer. Assuming its existence within a specific framework, it would define the mandates for conducting and maintaining security risk assessments, which continuous monitoring programs are designed to address by providing ongoing validation of control effectiveness and risk posture.
FIPS PUB 299 does not exist as a NIST publication.
Concept tested: Understanding relevant FIPS publications for continuous monitoring and risk assessment
Topics
Community Discussion
No community discussion yet for this question.