nerdexam
(ISC)2

CGRC · Question #119

A level of collaboration may be required between security and privacy control assessors with respect to controls that implemented to achieve both security and privacy objectives. Assessor findings…

The correct answer is A. A factual reporting on control effectiveness and discovered vulnerabilities. The question asks about the essential nature of assessor findings, particularly when security and privacy controls are assessed collaboratively.

Assessment/Audit of Security and Privacy Controls

Question

A level of collaboration may be required between security and privacy control assessors with respect to controls that implemented to achieve both security and privacy objectives. Assessor findings must be:

Response:

Options

  • AA factual reporting on control effectiveness and discovered vulnerabilities
  • BFindings and recommendations for remediation
  • CThe results of the control assessment
  • DAll of the above

How the community answered

(25 responses)
  • A
    96% (24)
  • B
    4% (1)

Why each option

The question asks about the essential nature of assessor findings, particularly when security and privacy controls are assessed collaboratively.

AA factual reporting on control effectiveness and discovered vulnerabilitiesCorrect

Assessor findings must primarily be a factual reporting of what was observed regarding control effectiveness and any identified vulnerabilities. They should be objective and based on evidence, representing an accurate account without subjective interpretation or immediate remediation prescriptions.

BFindings and recommendations for remediation

While recommendations for remediation often follow findings, the findings themselves are the objective, factual observations, not the recommendations.

CThe results of the control assessment

'The results of the control assessment' is too broad; findings are a specific component of those results, focused on objective observations.

DAll of the above

Since B and C are not solely the definition of 'assessor findings' in their most precise sense, 'All of the above' is incorrect.

Concept tested: Principles of security and privacy control assessment findings

Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53Ar5.pdf

Topics

#assessor findings#control effectiveness#vulnerability reporting#objective reporting

Community Discussion

No community discussion yet for this question.

Full CGRC Practice