nerdexam
(ISC)2

CGRC · Question #475

What is the name of the formal document that provides an overview of security requirements for the information system and describes the security controls in place or planned for meeting those requirem

The correct answer is C. System Security and Privacy Plan. The formal document that provides an overview of security requirements and describes the security controls for an information system is the System Security and Privacy Plan.

Implementation of Security and Privacy Controls

Question

What is the name of the formal document that provides an overview of security requirements for the information system and describes the security controls in place or planned for meeting those requirements? Response:

Options

  • ASecurity Assessment Plan (SAP)
  • BPlan of Action & Milestones (POA&M)
  • CSystem Security and Privacy Plan
  • DSecurity Assessment Report (SAR)

How the community answered

(48 responses)
  • A
    4% (2)
  • C
    94% (45)
  • D
    2% (1)

Why each option

The formal document that provides an overview of security requirements and describes the security controls for an information system is the System Security and Privacy Plan.

ASecurity Assessment Plan (SAP)

A Security Assessment Plan (SAP) outlines the methodology for assessing security controls, not the list of controls themselves.

BPlan of Action & Milestones (POA&M)

A Plan of Action & Milestones (POA&M) documents remediation plans for identified vulnerabilities, not the overall system security posture.

CSystem Security and Privacy PlanCorrect

The System Security and Privacy Plan (often referred to as System Security Plan or SSP) is a formal document that provides a comprehensive overview of an information system's security requirements. It details the security controls implemented or planned to meet those requirements, serving as a critical component in the risk management framework for demonstrating an organization's security posture.

DSecurity Assessment Report (SAR)

A Security Assessment Report (SAR) summarizes the findings of a security assessment, but it is not the plan describing the security controls.

Concept tested: System Security Plan (SSP) purpose

Source: csrc.nist.gov/publications/detail/sp/800-18/rev-1/archive/2006-02-14

Topics

#System Security Plan#NIST RMF#Security Documentation#Security Controls

Community Discussion

No community discussion yet for this question.

Full CGRC Practice