nerdexam
(ISC)2

CGRC · Question #194

Updating the security plan, security assessment report, and POAM based on results of the continuous monitoring process is what task in RMF Step 6, Monitor. Response:

The correct answer is A. Task 4, key updates. This question asks to identify the specific task within NIST RMF Step 6, Monitor, that involves updating security documentation based on continuous monitoring results.

Compliance Maintenance

Question

Updating the security plan, security assessment report, and POAM based on results of the continuous monitoring process is what task in RMF Step 6, Monitor. Response:

Options

  • ATask 4, key updates
  • BTask 1, key updates
  • CTask 3, key updates
  • DTask 2, key updates

How the community answered

(61 responses)
  • A
    87% (53)
  • B
    8% (5)
  • C
    2% (1)
  • D
    3% (2)

Why each option

This question asks to identify the specific task within NIST RMF Step 6, Monitor, that involves updating security documentation based on continuous monitoring results.

ATask 4, key updatesCorrect

In NIST SP 800-37 Rev. 2, Step 6, Monitor, Task 6-4 is "Update the Security Plan, Security Assessment Report, and Plan of Action and Milestones (POAM)." This task ensures that documentation remains current with the system's security posture and any changes identified through continuous monitoring activities.

BTask 1, key updates

Task 1 of Monitor is "Determine the security impact of changes to the system and its environment."

CTask 3, key updates

Task 3 of Monitor is "Conduct ongoing security assessments."

DTask 2, key updates

Task 2 of Monitor is "Conduct ongoing security monitoring activities."

Concept tested: NIST RMF Step 6 tasks

Source: https://csrc.nist.gov/publications/detail/sp/800-37/rev-2/final

Topics

#NIST RMF Step 6#Continuous Monitoring#Security Plan Updates#POAM

Community Discussion

No community discussion yet for this question.

Full CGRC Practice