CGRC · Question #452
Measure of confidence that the security features, practices, procedures, and architecture of an information system accurately mediates and enforces the security policy. Response:
The correct answer is A. Assurance. The question asks for the term that describes the level of confidence in an information system's ability to effectively implement and enforce its security policy through its features, practices, procedures, and architecture.
Question
Measure of confidence that the security features, practices, procedures, and architecture of an information system accurately mediates and enforces the security policy. Response:
Options
- AAssurance
- BAdversary
- CEnterprise
- DCountermeasure
How the community answered
(47 responses)- A87% (41)
- B2% (1)
- C2% (1)
- D9% (4)
Why each option
The question asks for the term that describes the level of confidence in an information system's ability to effectively implement and enforce its security policy through its features, practices, procedures, and architecture.
Assurance, in information security, refers to the degree of confidence that the security controls, architecture, and processes of an information system are correctly implemented, operate as intended, and are effective in enforcing the system's security policy. It is a critical component in the risk management framework, ensuring that a system adequately protects information.
An adversary is an individual, group, or organization that attempts to gain unauthorized access to an information system, which is unrelated to the confidence in security enforcement.
An enterprise refers to an organization or a business entity and not a measure of confidence in security.
A countermeasure is an action, device, procedure, technique, or other measure that reduces a vulnerability, not the confidence in overall policy enforcement.
Concept tested: Information System Security Assurance
Source: https://csrc.nist.gov/glossary/term/assurance
Topics
Community Discussion
No community discussion yet for this question.