nerdexam
(ISC)2

CGRC · Question #140

What will provide a mechanism for evaluating the functions the subsystems perform, interfaces with other subsystems and connections with other information systems, and how they have an impact on other

The correct answer is A. A security impact analysis. A 'security impact analysis' is the process of evaluating the potential effects of a change or event on the security of an information system, including how components interact and their overall impact, which allows for updating system design and security plans.

Security and Privacy Governance, Risk Management, and Compliance Program

Question

What will provide a mechanism for evaluating the functions the subsystems perform, interfaces with other subsystems and connections with other information systems, and how they have an impact on other subsystems and permit update of the system design and incorporation in the security plan. Response:

Options

  • AA security impact analysis
  • BA security impact connection
  • CA security control coincidence
  • DA insecurity trend analysis

How the community answered

(33 responses)
  • A
    91% (30)
  • B
    3% (1)
  • D
    6% (2)

Why each option

A 'security impact analysis' is the process of evaluating the potential effects of a change or event on the security of an information system, including how components interact and their overall impact, which allows for updating system design and security plans.

AA security impact analysisCorrect

A 'security impact analysis' is a systematic process of evaluating the potential security-related effects of a proposed change to an information system or its environment, or a potential security event. This analysis considers how changes in one part of the system (subsystems, interfaces, connections) can affect others, guiding updates to the system design and security plan to mitigate identified risks.

BA security impact connection

'Security impact connection' is not a recognized or standard term in information security.

CA security control coincidence

'Security control coincidence' refers to security controls that happen to be present together, not an analysis mechanism for system changes.

DA insecurity trend analysis

'Insecurity trend analysis' focuses on identifying patterns of vulnerabilities over time, not evaluating the impact of system functions, interfaces, and connections on system design and security plans.

Concept tested: Security Impact Analysis

Source: https://csrc.nist.gov/glossary/term/security_impact_analysis

Topics

#Security Impact Analysis#Risk Management#System Evaluation#Security Plan Updates

Community Discussion

No community discussion yet for this question.

Full CGRC Practice