CGRC · Question #354
Security control assessors can reuse past assessment results to satisfy the annual FISMA security assessment requirement provided the assessment results are: CHOOSE ALL THAT APPLY Response:
The correct answer is A. Relevant to the determination of control effectivemess B. Obtained by assessors with the required degree of independence C. Current. To reuse past security assessment results for annual FISMA requirements, the results must meet specific criteria regarding their quality and context.
Question
Security control assessors can reuse past assessment results to satisfy the annual FISMA security assessment requirement provided the assessment results are:
CHOOSE ALL THAT APPLY Response:
Options
- ARelevant to the determination of control effectivemess
- BObtained by assessors with the required degree of independence
- CCurrent
- DComplete
How the community answered
(37 responses)- A92% (34)
- D8% (3)
Why each option
To reuse past security assessment results for annual FISMA requirements, the results must meet specific criteria regarding their quality and context.
Assessment results must be relevant, meaning they directly apply to the current determination of control effectiveness for the system or environment being evaluated. This ensures the data provides meaningful insight into the present security posture.
The assessors who performed the original assessment must have had the required degree of independence to ensure an unbiased and objective evaluation. This is crucial for the trustworthiness and credibility of the assessment findings.
The assessment results must be current, reflecting the up-to-date state of the security controls and the operating environment. Outdated results would not accurately represent the system's current security posture or compliance.
While completeness is generally a desirable attribute for any assessment, it is not explicitly listed as one of the primary conditions for *reusing* past assessment results in the context of NIST/FISMA guidelines, which prioritize relevance, independence, and currency for validity.
Concept tested: FISMA security assessment reuse criteria
Source: https://csrc.nist.gov/publications/detail/sp/800-53a/rev-5/final
Topics
Community Discussion
No community discussion yet for this question.