CGRC · Question #153
Normally the requirements documented in the __________ ________ document will formulate the scope of SCA testing. Response:
The correct answer is A. Security Plan. The Security Plan outlines the security controls implemented for an information system, which directly defines the scope and areas of focus for Security Control Assessment (SCA) testing.
Question
Normally the requirements documented in the __________ ________ document will formulate the scope of SCA testing. Response:
Options
- ASecurity Plan
- BContingency Plan
- CAssessment Plan
- DRemediation plan
How the community answered
(30 responses)- A87% (26)
- B3% (1)
- C3% (1)
- D7% (2)
Why each option
The Security Plan outlines the security controls implemented for an information system, which directly defines the scope and areas of focus for Security Control Assessment (SCA) testing.
The Security Plan document comprehensively details the security controls selected, implemented, and planned for an information system, based on the system's categorization and risk assessment. These documented controls and their associated requirements in the Security Plan serve as the foundational baseline against which the Security Control Assessment (SCA) testing is performed, thereby formulating the scope of what needs to be assessed.
A Contingency Plan outlines procedures for incident response and recovery, but it does not primarily define the scope of security control assessments.
An Assessment Plan describes how an assessment will be conducted (methodology, schedule, resources), not what security requirements are being assessed.
A Remediation Plan details actions to fix identified vulnerabilities, which comes after an assessment, not before to define its scope.
Concept tested: Security Plan's role in SCA scope
Source: https://csrc.nist.gov/publications/detail/sp/800-18/rev-1/final
Topics
Community Discussion
No community discussion yet for this question.