nerdexam
(ISC)2

CGRC · Question #249

In which of the following phases do the system security plan update and the Plan of Action and Milestones (POAM) update take place? Response:

The correct answer is A. Continuous Monitoring Phase. The Continuous Monitoring Phase is where a system's security posture is continuously assessed and managed, necessitating regular updates to the System Security Plan (SSP) and Plan of Action and Milestones (POA&M). These updates reflect ongoing changes, new vulnerabilities, and im

Compliance Maintenance

Question

In which of the following phases do the system security plan update and the Plan of Action and Milestones (POAM) update take place? Response:

Options

  • AContinuous Monitoring Phase
  • BAccreditation Phase
  • CPreparation Phase
  • DDITSCAP Phase

How the community answered

(24 responses)
  • A
    96% (23)
  • D
    4% (1)

Why each option

The Continuous Monitoring Phase is where a system's security posture is continuously assessed and managed, necessitating regular updates to the System Security Plan (SSP) and Plan of Action and Milestones (POA&M). These updates reflect ongoing changes, new vulnerabilities, and implemented remediation efforts.

AContinuous Monitoring PhaseCorrect

The Continuous Monitoring Phase, as part of the Risk Management Framework (RMF), involves ongoing assessment of security controls, documenting security posture, and making risk-based decisions. During this phase, the System Security Plan (SSP) is regularly updated to reflect changes in the system, its environment, or its controls, and the Plan of Action and Milestones (POA&M) is continuously updated to track identified deficiencies and their remediation status. This ensures the system maintains an acceptable security posture throughout its lifecycle.

BAccreditation Phase

The Accreditation Phase (or Authorize phase in RMF) is where the authorizing official makes a risk-based decision to authorize system operation, but ongoing updates occur in continuous monitoring, not primarily during accreditation itself.

CPreparation Phase

The Preparation Phase (or Categorize and Select in RMF) involves defining the system and its security requirements, but not the ongoing operational updates to the SSP and POA&M.

DDITSCAP Phase

DITSCAP (Defense Information Technology Security Certification and Accreditation Process) is an older, superseded framework, not a current RMF phase where these updates primarily occur.

Concept tested: RMF Continuous Monitoring activities

Source: https://csrc.nist.gov/glossary/term/continuous_monitoring

Topics

#Continuous Monitoring#System Security Plan (SSP)#Plan of Action and Milestones (POAM)#NIST RMF

Community Discussion

No community discussion yet for this question.

Full CGRC Practice