CGRC · Question #313
When does monitoring security controls take place? Response:
The correct answer is B. After the initial system security authorization. Continuous monitoring of security controls is an ongoing process that primarily occurs after a system has received its initial security authorization to ensure its continued compliance and risk posture.
Question
When does monitoring security controls take place? Response:
Options
- ABefore the initial system certification
- BAfter the initial system security authorization
- CBefore and after the initial system security accreditation
- DDuring the system design phase
How the community answered
(30 responses)- A7% (2)
- B87% (26)
- C3% (1)
- D3% (1)
Why each option
Continuous monitoring of security controls is an ongoing process that primarily occurs after a system has received its initial security authorization to ensure its continued compliance and risk posture.
Before initial system certification, controls are assessed for effectiveness, but continuous monitoring is typically a post-certification or post-authorization activity.
Monitoring security controls is an essential part of the ongoing authorization process, which begins after the initial system security authorization (or accreditation) is granted. This continuous activity ensures that controls remain effective and that the system's risk posture is managed throughout its lifecycle.
While assessment happens before accreditation, ongoing monitoring is primarily an activity that occurs after the initial security accreditation to ensure continued effectiveness, making 'before and after' misleading for continuous monitoring.
During the system design phase, security requirements are defined and controls are designed, but the actual monitoring of implemented controls occurs in later lifecycle phases.
Concept tested: Timing of security control monitoring
Source: https://csrc.nist.gov/glossary/term/continuous-monitoring
Topics
Community Discussion
No community discussion yet for this question.