nerdexam
(ISC)2

CGRC · Question #302

Which plan documents objectives for the security control assessment & details how to conduct such an assessment and records assessment procedures (Security Plan, Assessment Plan, POAM)? Response:

The correct answer is A. Assessment Plan. The Assessment Plan is the document that specifies the objectives, methods, and procedures for conducting a security control assessment.

Assessment/Audit of Security and Privacy Controls

Question

Which plan documents objectives for the security control assessment & details how to conduct such an assessment and records assessment procedures (Security Plan, Assessment Plan, POAM)? Response:

Options

  • AAssessment Plan
  • BSecurity Plan
  • CPOAM
  • DContingency Plan

How the community answered

(43 responses)
  • A
    86% (37)
  • B
    7% (3)
  • C
    2% (1)
  • D
    5% (2)

Why each option

The Assessment Plan is the document that specifies the objectives, methods, and procedures for conducting a security control assessment.

AAssessment PlanCorrect

An Assessment Plan thoroughly outlines how a security control assessment will be conducted, detailing the scope, methodologies, procedures, and resources required. This document ensures that the assessment is systematic, comprehensive, and aligns with the organization's security objectives.

BSecurity Plan

A Security Plan describes the security controls chosen for a system and their implementation, not how they are assessed.

CPOAM

A POAM (Plan of Action and Milestones) identifies security weaknesses and outlines planned remediation efforts.

DContingency Plan

A Contingency Plan focuses on procedures for incident response and disaster recovery, not security control assessment.

Concept tested: RMF Documentation - Assessment Plan

Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53Ar5.pdf

Topics

#Security Control Assessment#Assessment Plan#NIST RMF#Documentation

Community Discussion

No community discussion yet for this question.

Full CGRC Practice