nerdexam
(ISC)2

CGRC · Question #208

One of the following is a formal document that provides an overview of the security requirements for the information system, describes the system and the security controls in place or planned for…

The correct answer is B. Security Plan (SP). This question asks to identify the formal document that provides an overview of an information system's security requirements, description, and its security controls.

Selection and Approval of Framework, Security, and Privacy Controls

Question

One of the following is a formal document that provides an overview of the security requirements for the information system, describes the system and the security controls in place or planned for meeting those requirements. Response:

Options

  • AInitial Risk Assessment
  • BSecurity Plan (SP)
  • CSecurity and Privacy assessment reports
  • DPlan of Action and Milestones (POA&M)

How the community answered

(35 responses)
  • A
    6% (2)
  • B
    91% (32)
  • C
    3% (1)

Why each option

This question asks to identify the formal document that provides an overview of an information system's security requirements, description, and its security controls.

AInitial Risk Assessment

An Initial Risk Assessment identifies potential risks early on but does not provide a comprehensive description of the system or its implemented security controls.

BSecurity Plan (SP)Correct

A Security Plan (SP) is a formal document that details an information system, its boundaries, its security requirements, and the specific security controls that are implemented or planned to meet those requirements. It is a foundational document in the system authorization process.

CSecurity and Privacy assessment reports

Security and Privacy Assessment Reports document the results of control assessments, providing evidence of control effectiveness, but they are not the primary document describing the system and its controls.

DPlan of Action and Milestones (POA&M)

A Plan of Action and Milestones (POA&M) is used to track the remediation of identified security weaknesses, not to initially describe the system and its security controls.

Concept tested: NIST RMF Security Plan document

Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-18r1.pdf

Topics

#Security Plan (SP)#System Security Plan (SSP)#NIST RMF#Documentation

Community Discussion

No community discussion yet for this question.

Full CGRC Practice