CGRC · Question #421
Controls reported by system owner as not in place should not be tested but needs to be recorded as (passing, failing, of N/A) since report is basis for remediation plan. Response:
The correct answer is A. Failing. If a system owner reports that a control is not implemented, it should be recorded as 'Failing' in the security assessment report. This status indicates non-compliance and forms the basis for developing a remediation plan.
Question
Controls reported by system owner as not in place should not be tested but needs to be recorded as (passing, failing, of N/A) since report is basis for remediation plan. Response:
Options
- AFailing
- BPassing
- CScoping
- DTailoring
How the community answered
(53 responses)- A75% (40)
- B13% (7)
- C8% (4)
- D4% (2)
Why each option
If a system owner reports that a control is not implemented, it should be recorded as 'Failing' in the security assessment report. This status indicates non-compliance and forms the basis for developing a remediation plan.
When a control is explicitly reported by the system owner as not being in place, it directly indicates that the control objective is not met. Recording it as 'Failing' accurately reflects its non-implementation and triggers the need for corrective actions within a remediation plan.
Recording a non-implemented control as 'Passing' would inaccurately suggest compliance and prevent its inclusion in a remediation plan.
'Scoping' refers to determining the applicability of controls to a system, not a status for non-implemented controls.
'Tailoring' involves modifying controls to fit specific organizational or system circumstances, not a status for non-implemented controls.
Concept tested: Control assessment status reporting
Source: https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-53Ar1.pdf
Topics
Community Discussion
No community discussion yet for this question.