CGRC · Question #48
True or False; After an ATO is granted, ongoing continuous monitoring is performed on all identified security controls as well as physical environment, etc.. Response:
The correct answer is A. True. True; Following the granting of an Authority to Operate (ATO), continuous monitoring is indeed performed on all identified security controls and the physical environment. This ongoing activity ensures the system's security posture remains effective and compliant throughout its…
Question
True or False; After an ATO is granted, ongoing continuous monitoring is performed on all identified security controls as well as physical environment, etc.. Response:
Options
- ATrue
- BFalse
How the community answered
(49 responses)- A88% (43)
- B12% (6)
Why each option
True; Following the granting of an Authority to Operate (ATO), continuous monitoring is indeed performed on all identified security controls and the physical environment. This ongoing activity ensures the system's security posture remains effective and compliant throughout its operational existence.
True. After an Authority to Operate (ATO) is granted, continuous monitoring becomes crucial to maintain the system's security posture and ensure ongoing compliance with established security requirements. This includes monitoring all identified security controls, the physical environment, and other relevant system parameters to detect changes, vulnerabilities, and threats in a timely manner.
False, because continuous monitoring is a mandatory and essential activity that occurs throughout the operational phase of an information system's lifecycle, continuing after an ATO is issued.
Concept tested: Continuous monitoring after ATO
Source: https://csrc.nist.gov/projects/risk-management-framework-rmf/rmf-steps/monitor
Topics
Community Discussion
No community discussion yet for this question.