nerdexam
(ISC)2

CGRC · Question #452

Measure of confidence that the security features, practices, procedures, and architecture of an information system accurately mediates and enforces the security policy. Response:

The correct answer is A. Assurance. The question asks for the term that describes the level of confidence in an information system's ability to effectively implement and enforce its security policy through its features, practices, procedures, and architecture.

Security and Privacy Governance, Risk Management, and Compliance Program

Question

Measure of confidence that the security features, practices, procedures, and architecture of an information system accurately mediates and enforces the security policy. Response:

Options

  • AAssurance
  • BAdversary
  • CEnterprise
  • DCountermeasure

How the community answered

(47 responses)
  • A
    87% (41)
  • B
    2% (1)
  • C
    2% (1)
  • D
    9% (4)

Why each option

The question asks for the term that describes the level of confidence in an information system's ability to effectively implement and enforce its security policy through its features, practices, procedures, and architecture.

AAssuranceCorrect

Assurance, in information security, refers to the degree of confidence that the security controls, architecture, and processes of an information system are correctly implemented, operate as intended, and are effective in enforcing the system's security policy. It is a critical component in the risk management framework, ensuring that a system adequately protects information.

BAdversary

An adversary is an individual, group, or organization that attempts to gain unauthorized access to an information system, which is unrelated to the confidence in security enforcement.

CEnterprise

An enterprise refers to an organization or a business entity and not a measure of confidence in security.

DCountermeasure

A countermeasure is an action, device, procedure, technique, or other measure that reduces a vulnerability, not the confidence in overall policy enforcement.

Concept tested: Information System Security Assurance

Source: https://csrc.nist.gov/glossary/term/assurance

Topics

#Assurance#Security Policy Enforcement#System Confidence#Governance

Community Discussion

No community discussion yet for this question.

Full CGRC Practice