CGRC · Question #287
Any deviations from the Security Assessment plan should be________? Response:
The correct answer is D. documented, emailed and flagged. All deviations from a Security Assessment plan should be formally documented, communicated via email, and flagged for review to ensure transparency and proper risk management.
Question
Any deviations from the Security Assessment plan should be________? Response:
Options
- Adocumented
- Bemailed
- Cflagged
- Ddocumented, emailed and flagged
How the community answered
(55 responses)- A2% (1)
- B5% (3)
- C2% (1)
- D91% (50)
Why each option
All deviations from a Security Assessment plan should be formally documented, communicated via email, and flagged for review to ensure transparency and proper risk management.
While documentation is essential, it alone is insufficient without communicating and highlighting the deviation.
Emailing is important for communication but without documentation and flagging, the deviation may not be properly recorded or prioritized.
Flagging ensures visibility but without documentation and broader communication, the context and impact may be lost.
When deviations occur during a security assessment, it is crucial to document them to maintain an audit trail and accountability. Emailing ensures that all relevant stakeholders are informed promptly, and flagging them ensures they are highlighted for immediate attention, review, and potential remediation, supporting comprehensive risk management.
Concept tested: Security assessment deviation management
Topics
Community Discussion
No community discussion yet for this question.