nerdexam
(ISC)2

CGRC · Question #287

Any deviations from the Security Assessment plan should be________? Response:

The correct answer is D. documented, emailed and flagged. All deviations from a Security Assessment plan should be formally documented, communicated via email, and flagged for review to ensure transparency and proper risk management.

Assessment/Audit of Security and Privacy Controls

Question

Any deviations from the Security Assessment plan should be________? Response:

Options

  • Adocumented
  • Bemailed
  • Cflagged
  • Ddocumented, emailed and flagged

How the community answered

(55 responses)
  • A
    2% (1)
  • B
    5% (3)
  • C
    2% (1)
  • D
    91% (50)

Why each option

All deviations from a Security Assessment plan should be formally documented, communicated via email, and flagged for review to ensure transparency and proper risk management.

Adocumented

While documentation is essential, it alone is insufficient without communicating and highlighting the deviation.

Bemailed

Emailing is important for communication but without documentation and flagging, the deviation may not be properly recorded or prioritized.

Cflagged

Flagging ensures visibility but without documentation and broader communication, the context and impact may be lost.

Ddocumented, emailed and flaggedCorrect

When deviations occur during a security assessment, it is crucial to document them to maintain an audit trail and accountability. Emailing ensures that all relevant stakeholders are informed promptly, and flagging them ensures they are highlighted for immediate attention, review, and potential remediation, supporting comprehensive risk management.

Concept tested: Security assessment deviation management

Topics

#Security Assessment Process#Deviation Handling#Reporting Procedures#Compliance Documentation

Community Discussion

No community discussion yet for this question.

Full CGRC Practice