nerdexam
(ISC)2

CGRC · Question #179

A General principle is that the scope of certification testing should include all controls defined in what document; SAR, SP, POAM? Response:

The correct answer is A. Security Plan. Certification testing must comprehensively include all security controls officially documented and defined within the Security Plan for an information system.

Selection and Approval of Framework, Security, and Privacy Controls

Question

A General principle is that the scope of certification testing should include all controls defined in what document; SAR, SP, POAM? Response:

Options

  • ASecurity Plan
  • BAssessment Plan
  • CContingency Plan
  • DRemediation plan

How the community answered

(31 responses)
  • A
    90% (28)
  • B
    3% (1)
  • D
    6% (2)

Why each option

Certification testing must comprehensively include all security controls officially documented and defined within the Security Plan for an information system.

ASecurity PlanCorrect

The Security Plan (SP) is the official document that formally describes the security controls implemented for an information system, detailing how they protect the system and its data. Therefore, certification testing must specifically verify the effectiveness of all controls outlined in this foundational document to ensure compliance and adequate protection.

BAssessment Plan

An Assessment Plan details *how* controls will be tested (methods, procedures, resources), not *which* controls are implemented within the system.

CContingency Plan

A Contingency Plan outlines procedures for emergency response and recovery, which is distinct from the operational security controls subject to certification testing.

DRemediation plan

A Remediation Plan addresses identified weaknesses after an assessment, but it is not the primary document defining the initial scope of controls for certification.

Concept tested: Security Plan and certification scope

Source: https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-18r1.pdf

Topics

#Security Plan#Certification Testing#Control Definition#System Authorization

Community Discussion

No community discussion yet for this question.

Full CGRC Practice