CGRC · Question #397
This process is used to determine if the security controls in the information system continue to be effective over time in light of the inevitable changes that occur in the system as well as the…
The correct answer is A. Continuous monitoring. This process involves continually assessing the effectiveness of security controls over time, particularly in response to system and environmental changes between authorization decisions.
Question
This process is used to determine if the security controls in the information system continue to be effective over time in light of the inevitable changes that occur in the system as well as the environment in which the system operates between authorization decisions. Response:
Options
- AContinuous monitoring
- BConfiguration management
- CVulnerability assessment
- DCertification and accreditation
How the community answered
(37 responses)- A89% (33)
- B3% (1)
- C3% (1)
- D5% (2)
Why each option
This process involves continually assessing the effectiveness of security controls over time, particularly in response to system and environmental changes between authorization decisions.
Continuous monitoring is an ongoing process designed to keep security controls effective by regularly assessing them for changes in the system or operating environment. This ensures that the security posture remains acceptable between formal authorization decisions.
Configuration management focuses on maintaining the consistency of a system's configuration, not specifically the ongoing effectiveness of security controls in response to broader changes.
Vulnerability assessment is a point-in-time activity to identify security weaknesses, not a continuous process to determine overall control effectiveness over time.
Certification and accreditation (now often referred to as authorization) are discrete events that grant official approval for a system to operate, not an ongoing process of monitoring effectiveness.
Concept tested: Definition of continuous monitoring (NIST RMF)
Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-137a.pdf
Topics
Community Discussion
No community discussion yet for this question.