nerdexam
(ISC)2

CGRC · Question #153

Normally the requirements documented in the __________ ________ document will formulate the scope of SCA testing. Response:

The correct answer is A. Security Plan. The Security Plan outlines the security controls implemented for an information system, which directly defines the scope and areas of focus for Security Control Assessment (SCA) testing.

Selection and Approval of Framework, Security, and Privacy Controls

Question

Normally the requirements documented in the __________ ________ document will formulate the scope of SCA testing. Response:

Options

  • ASecurity Plan
  • BContingency Plan
  • CAssessment Plan
  • DRemediation plan

How the community answered

(30 responses)
  • A
    87% (26)
  • B
    3% (1)
  • C
    3% (1)
  • D
    7% (2)

Why each option

The Security Plan outlines the security controls implemented for an information system, which directly defines the scope and areas of focus for Security Control Assessment (SCA) testing.

ASecurity PlanCorrect

The Security Plan document comprehensively details the security controls selected, implemented, and planned for an information system, based on the system's categorization and risk assessment. These documented controls and their associated requirements in the Security Plan serve as the foundational baseline against which the Security Control Assessment (SCA) testing is performed, thereby formulating the scope of what needs to be assessed.

BContingency Plan

A Contingency Plan outlines procedures for incident response and recovery, but it does not primarily define the scope of security control assessments.

CAssessment Plan

An Assessment Plan describes how an assessment will be conducted (methodology, schedule, resources), not what security requirements are being assessed.

DRemediation plan

A Remediation Plan details actions to fix identified vulnerabilities, which comes after an assessment, not before to define its scope.

Concept tested: Security Plan's role in SCA scope

Source: https://csrc.nist.gov/publications/detail/sp/800-18/rev-1/final

Topics

#Security Plan#SCA Testing Scope#Risk Management Framework#NIST Documents

Community Discussion

No community discussion yet for this question.

Full CGRC Practice