CGRC · Question #140
What will provide a mechanism for evaluating the functions the subsystems perform, interfaces with other subsystems and connections with other information systems, and how they have an impact on other
The correct answer is A. A security impact analysis. A 'security impact analysis' is the process of evaluating the potential effects of a change or event on the security of an information system, including how components interact and their overall impact, which allows for updating system design and security plans.
Question
What will provide a mechanism for evaluating the functions the subsystems perform, interfaces with other subsystems and connections with other information systems, and how they have an impact on other subsystems and permit update of the system design and incorporation in the security plan. Response:
Options
- AA security impact analysis
- BA security impact connection
- CA security control coincidence
- DA insecurity trend analysis
How the community answered
(33 responses)- A91% (30)
- B3% (1)
- D6% (2)
Why each option
A 'security impact analysis' is the process of evaluating the potential effects of a change or event on the security of an information system, including how components interact and their overall impact, which allows for updating system design and security plans.
A 'security impact analysis' is a systematic process of evaluating the potential security-related effects of a proposed change to an information system or its environment, or a potential security event. This analysis considers how changes in one part of the system (subsystems, interfaces, connections) can affect others, guiding updates to the system design and security plan to mitigate identified risks.
'Security impact connection' is not a recognized or standard term in information security.
'Security control coincidence' refers to security controls that happen to be present together, not an analysis mechanism for system changes.
'Insecurity trend analysis' focuses on identifying patterns of vulnerabilities over time, not evaluating the impact of system functions, interfaces, and connections on system design and security plans.
Concept tested: Security Impact Analysis
Source: https://csrc.nist.gov/glossary/term/security_impact_analysis
Topics
Community Discussion
No community discussion yet for this question.