CGRC · Question #302
Which plan documents objectives for the security control assessment & details how to conduct such an assessment and records assessment procedures (Security Plan, Assessment Plan, POAM)? Response:
The correct answer is A. Assessment Plan. The Assessment Plan is the document that specifies the objectives, methods, and procedures for conducting a security control assessment.
Question
Which plan documents objectives for the security control assessment & details how to conduct such an assessment and records assessment procedures (Security Plan, Assessment Plan, POAM)? Response:
Options
- AAssessment Plan
- BSecurity Plan
- CPOAM
- DContingency Plan
How the community answered
(43 responses)- A86% (37)
- B7% (3)
- C2% (1)
- D5% (2)
Why each option
The Assessment Plan is the document that specifies the objectives, methods, and procedures for conducting a security control assessment.
An Assessment Plan thoroughly outlines how a security control assessment will be conducted, detailing the scope, methodologies, procedures, and resources required. This document ensures that the assessment is systematic, comprehensive, and aligns with the organization's security objectives.
A Security Plan describes the security controls chosen for a system and their implementation, not how they are assessed.
A POAM (Plan of Action and Milestones) identifies security weaknesses and outlines planned remediation efforts.
A Contingency Plan focuses on procedures for incident response and disaster recovery, not security control assessment.
Concept tested: RMF Documentation - Assessment Plan
Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53Ar5.pdf
Topics
Community Discussion
No community discussion yet for this question.