nerdexam
(ISC)2

CGRC · Question #311

Significant changes to a system may trigger an event-driven authorization action which may include by are not limited to all of the following except one. Choose the exception. Response:

The correct answer is F. Moving to a new facility. Event-driven authorization actions are triggered by significant technical or operational changes to an information system, but not typically by a physical relocation of the system.

Compliance Maintenance

Question

Significant changes to a system may trigger an event-driven authorization action which may include by are not limited to all of the following except one. Choose the exception. Response:

Options

  • AModifications to system ports protocols and services
  • BInstallation of a new or upgraded operating system, middleware component, or application
  • CModifications to how information, including PII, is processed
  • DChanges in information types processed, stored, or transmitted by the system
  • EModifications to security and privacy controls
  • FMoving to a new facility

How the community answered

(20 responses)
  • C
    10% (2)
  • D
    5% (1)
  • E
    5% (1)
  • F
    80% (16)

Why each option

Event-driven authorization actions are triggered by significant technical or operational changes to an information system, but not typically by a physical relocation of the system.

AModifications to system ports protocols and services

Modifications to system ports, protocols, and services directly impact the system's attack surface and functionality, requiring potential re-authorization as an event-driven action.

BInstallation of a new or upgraded operating system, middleware component, or application

Installation of new or upgraded software components introduces new code and configurations that can significantly alter the system's security posture, necessitating re-evaluation and event-driven authorization.

CModifications to how information, including PII, is processed

Changes in how information, including PII, is processed can have major privacy and security implications, triggering an event-driven authorization review.

DChanges in information types processed, stored, or transmitted by the system

Changes in the types of information processed, stored, or transmitted by the system directly affect its data classification and protection requirements, necessitating event-driven authorization actions.

EModifications to security and privacy controls

Modifications to security and privacy controls fundamentally change the system's defense mechanisms and compliance, requiring an event-driven authorization review.

FMoving to a new facilityCorrect

Moving to a new facility is a physical change, whereas event-driven authorization actions primarily respond to changes in the system's technical configuration, data handling, or security posture that directly impact its risk profile or compliance. While a move might necessitate a new authorization, it's not categorized as an 'event-driven authorization action' in the same vein as direct system modifications.

Concept tested: Event-driven authorization triggers

Source: https://csrc.nist.gov/publications/detail/sp/800-37/rev-2/final

Topics

#Event-driven authorization#System change management#Continuous monitoring#Authorization triggers

Community Discussion

No community discussion yet for this question.

Full CGRC Practice