CGRC · Question #179
A General principle is that the scope of certification testing should include all controls defined in what document; SAR, SP, POAM? Response:
The correct answer is A. Security Plan. Certification testing must comprehensively include all security controls officially documented and defined within the Security Plan for an information system.
Question
A General principle is that the scope of certification testing should include all controls defined in what document; SAR, SP, POAM? Response:
Options
- ASecurity Plan
- BAssessment Plan
- CContingency Plan
- DRemediation plan
How the community answered
(31 responses)- A90% (28)
- B3% (1)
- D6% (2)
Why each option
Certification testing must comprehensively include all security controls officially documented and defined within the Security Plan for an information system.
The Security Plan (SP) is the official document that formally describes the security controls implemented for an information system, detailing how they protect the system and its data. Therefore, certification testing must specifically verify the effectiveness of all controls outlined in this foundational document to ensure compliance and adequate protection.
An Assessment Plan details *how* controls will be tested (methods, procedures, resources), not *which* controls are implemented within the system.
A Contingency Plan outlines procedures for emergency response and recovery, which is distinct from the operational security controls subject to certification testing.
A Remediation Plan addresses identified weaknesses after an assessment, but it is not the primary document defining the initial scope of controls for certification.
Concept tested: Security Plan and certification scope
Source: https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-18r1.pdf
Topics
Community Discussion
No community discussion yet for this question.