nerdexam
(ISC)2

CGRC · Question #348

Why is security control volatility an important consideration in the development of a security control monitoring strategy? Response:

The correct answer is B. It indicates a need for compensating controls. Security control volatility is an important consideration in monitoring strategy because controls prone to frequent changes may require compensating controls to maintain an adequate security posture.

Compliance Maintenance

Question

Why is security control volatility an important consideration in the development of a security control monitoring strategy? Response:

Options

  • AIt identifies needed security control monitoring exceptions.
  • BIt indicates a need for compensating controls.
  • CIt establishes priority for security control monitoring.
  • DIt provides justification for revisions to the configuration management and control plan.

How the community answered

(64 responses)
  • A
    2% (1)
  • B
    83% (53)
  • C
    5% (3)
  • D
    11% (7)

Why each option

Security control volatility is an important consideration in monitoring strategy because controls prone to frequent changes may require compensating controls to maintain an adequate security posture.

AIt identifies needed security control monitoring exceptions.

While volatility might necessitate exceptions, its primary importance is identifying the underlying instability that might require more robust mitigation, rather than just documenting deviations.

BIt indicates a need for compensating controls.Correct

Security control volatility, referring to controls that are frequently updated or easily impacted by system modifications, directly indicates that existing security measures might not be stable or consistently effective over time, thus signaling a critical need for alternative or compensating controls to mitigate the associated risks and maintain continuous protection.

CIt establishes priority for security control monitoring.

While volatility could influence monitoring priority, its more direct and fundamental implication for overall security control strategy is the need for alternative or compensatory mitigation methods.

DIt provides justification for revisions to the configuration management and control plan.

Volatility may inform configuration management, but it more directly points to a security gap or weakness that might require a compensating control, rather than merely providing justification for revisions to a plan.

Concept tested: Security control volatility and compensating controls

Source: https://csrc.nist.gov/glossary/term/compensating-security-control

Topics

#Security Control Monitoring#Control Volatility#Compensating Controls#Risk Management

Community Discussion

No community discussion yet for this question.

Full CGRC Practice