nerdexam
(ISC)2

CGRC · Question #397

This process is used to determine if the security controls in the information system continue to be effective over time in light of the inevitable changes that occur in the system as well as the…

The correct answer is A. Continuous monitoring. This process involves continually assessing the effectiveness of security controls over time, particularly in response to system and environmental changes between authorization decisions.

Compliance Maintenance

Question

This process is used to determine if the security controls in the information system continue to be effective over time in light of the inevitable changes that occur in the system as well as the environment in which the system operates between authorization decisions. Response:

Options

  • AContinuous monitoring
  • BConfiguration management
  • CVulnerability assessment
  • DCertification and accreditation

How the community answered

(37 responses)
  • A
    89% (33)
  • B
    3% (1)
  • C
    3% (1)
  • D
    5% (2)

Why each option

This process involves continually assessing the effectiveness of security controls over time, particularly in response to system and environmental changes between authorization decisions.

AContinuous monitoringCorrect

Continuous monitoring is an ongoing process designed to keep security controls effective by regularly assessing them for changes in the system or operating environment. This ensures that the security posture remains acceptable between formal authorization decisions.

BConfiguration management

Configuration management focuses on maintaining the consistency of a system's configuration, not specifically the ongoing effectiveness of security controls in response to broader changes.

CVulnerability assessment

Vulnerability assessment is a point-in-time activity to identify security weaknesses, not a continuous process to determine overall control effectiveness over time.

DCertification and accreditation

Certification and accreditation (now often referred to as authorization) are discrete events that grant official approval for a system to operate, not an ongoing process of monitoring effectiveness.

Concept tested: Definition of continuous monitoring (NIST RMF)

Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-137a.pdf

Topics

#Continuous Monitoring#Security Control Effectiveness#Risk Management Framework#System Authorization

Community Discussion

No community discussion yet for this question.

Full CGRC Practice