CGRC · Question #311
Significant changes to a system may trigger an event-driven authorization action which may include by are not limited to all of the following except one. Choose the exception. Response:
The correct answer is F. Moving to a new facility. Event-driven authorization actions are triggered by significant technical or operational changes to an information system, but not typically by a physical relocation of the system.
Question
Significant changes to a system may trigger an event-driven authorization action which may include by are not limited to all of the following except one. Choose the exception. Response:
Options
- AModifications to system ports protocols and services
- BInstallation of a new or upgraded operating system, middleware component, or application
- CModifications to how information, including PII, is processed
- DChanges in information types processed, stored, or transmitted by the system
- EModifications to security and privacy controls
- FMoving to a new facility
How the community answered
(20 responses)- C10% (2)
- D5% (1)
- E5% (1)
- F80% (16)
Why each option
Event-driven authorization actions are triggered by significant technical or operational changes to an information system, but not typically by a physical relocation of the system.
Modifications to system ports, protocols, and services directly impact the system's attack surface and functionality, requiring potential re-authorization as an event-driven action.
Installation of new or upgraded software components introduces new code and configurations that can significantly alter the system's security posture, necessitating re-evaluation and event-driven authorization.
Changes in how information, including PII, is processed can have major privacy and security implications, triggering an event-driven authorization review.
Changes in the types of information processed, stored, or transmitted by the system directly affect its data classification and protection requirements, necessitating event-driven authorization actions.
Modifications to security and privacy controls fundamentally change the system's defense mechanisms and compliance, requiring an event-driven authorization review.
Moving to a new facility is a physical change, whereas event-driven authorization actions primarily respond to changes in the system's technical configuration, data handling, or security posture that directly impact its risk profile or compliance. While a move might necessitate a new authorization, it's not categorized as an 'event-driven authorization action' in the same vein as direct system modifications.
Concept tested: Event-driven authorization triggers
Source: https://csrc.nist.gov/publications/detail/sp/800-37/rev-2/final
Topics
Community Discussion
No community discussion yet for this question.