CGRC · Question #249
In which of the following phases do the system security plan update and the Plan of Action and Milestones (POAM) update take place? Response:
The correct answer is A. Continuous Monitoring Phase. The Continuous Monitoring Phase is where a system's security posture is continuously assessed and managed, necessitating regular updates to the System Security Plan (SSP) and Plan of Action and Milestones (POA&M). These updates reflect ongoing changes, new vulnerabilities, and im
Question
In which of the following phases do the system security plan update and the Plan of Action and Milestones (POAM) update take place? Response:
Options
- AContinuous Monitoring Phase
- BAccreditation Phase
- CPreparation Phase
- DDITSCAP Phase
How the community answered
(24 responses)- A96% (23)
- D4% (1)
Why each option
The Continuous Monitoring Phase is where a system's security posture is continuously assessed and managed, necessitating regular updates to the System Security Plan (SSP) and Plan of Action and Milestones (POA&M). These updates reflect ongoing changes, new vulnerabilities, and implemented remediation efforts.
The Continuous Monitoring Phase, as part of the Risk Management Framework (RMF), involves ongoing assessment of security controls, documenting security posture, and making risk-based decisions. During this phase, the System Security Plan (SSP) is regularly updated to reflect changes in the system, its environment, or its controls, and the Plan of Action and Milestones (POA&M) is continuously updated to track identified deficiencies and their remediation status. This ensures the system maintains an acceptable security posture throughout its lifecycle.
The Accreditation Phase (or Authorize phase in RMF) is where the authorizing official makes a risk-based decision to authorize system operation, but ongoing updates occur in continuous monitoring, not primarily during accreditation itself.
The Preparation Phase (or Categorize and Select in RMF) involves defining the system and its security requirements, but not the ongoing operational updates to the SSP and POA&M.
DITSCAP (Defense Information Technology Security Certification and Accreditation Process) is an older, superseded framework, not a current RMF phase where these updates primarily occur.
Concept tested: RMF Continuous Monitoring activities
Source: https://csrc.nist.gov/glossary/term/continuous_monitoring
Topics
Community Discussion
No community discussion yet for this question.