nerdexam
(ISC)2

CGRC · Question #354

Security control assessors can reuse past assessment results to satisfy the annual FISMA security assessment requirement provided the assessment results are: CHOOSE ALL THAT APPLY Response:

The correct answer is A. Relevant to the determination of control effectivemess B. Obtained by assessors with the required degree of independence C. Current. To reuse past security assessment results for annual FISMA requirements, the results must meet specific criteria regarding their quality and context.

Assessment/Audit of Security and Privacy Controls

Question

Security control assessors can reuse past assessment results to satisfy the annual FISMA security assessment requirement provided the assessment results are:

CHOOSE ALL THAT APPLY Response:

Options

  • ARelevant to the determination of control effectivemess
  • BObtained by assessors with the required degree of independence
  • CCurrent
  • DComplete

How the community answered

(37 responses)
  • A
    92% (34)
  • D
    8% (3)

Why each option

To reuse past security assessment results for annual FISMA requirements, the results must meet specific criteria regarding their quality and context.

ARelevant to the determination of control effectivemessCorrect

Assessment results must be relevant, meaning they directly apply to the current determination of control effectiveness for the system or environment being evaluated. This ensures the data provides meaningful insight into the present security posture.

BObtained by assessors with the required degree of independenceCorrect

The assessors who performed the original assessment must have had the required degree of independence to ensure an unbiased and objective evaluation. This is crucial for the trustworthiness and credibility of the assessment findings.

CCurrentCorrect

The assessment results must be current, reflecting the up-to-date state of the security controls and the operating environment. Outdated results would not accurately represent the system's current security posture or compliance.

DComplete

While completeness is generally a desirable attribute for any assessment, it is not explicitly listed as one of the primary conditions for *reusing* past assessment results in the context of NIST/FISMA guidelines, which prioritize relevance, independence, and currency for validity.

Concept tested: FISMA security assessment reuse criteria

Source: https://csrc.nist.gov/publications/detail/sp/800-53a/rev-5/final

Topics

#FISMA#Security Assessment#Assessment Reuse#Control Effectiveness

Community Discussion

No community discussion yet for this question.

Full CGRC Practice