CGRC · Question #486
The change control board team at Colvine Tech has determined the security impact of proposed changes to an application, what would be the team's next action? Response:
The correct answer is A. Update the SSP, SAR, and POA&Ms based on the results of the change control board's security. After a change control board determines the security impact of proposed changes, the logical next step is to update official documentation like the System Security Plan (SSP), Security Assessment Report (SAR), and Plan of Action and Milestones (POA&M) to reflect these impacts…
Question
The change control board team at Colvine Tech has determined the security impact of proposed changes to an application, what would be the team's next action? Response:
Options
- AUpdate the SSP, SAR, and POA&Ms based on the results of the change control board's security
- BAssess a selected subset of the security controls employed within and inherited by the application
- CPrepare the SAR documenting the issues, findings, and recommendations from the security
- DPrepare the POA&Ms based on the findings and recommendations of the security assessment
How the community answered
(25 responses)- A72% (18)
- B4% (1)
- C8% (2)
- D16% (4)
Why each option
After a change control board determines the security impact of proposed changes, the logical next step is to update official documentation like the System Security Plan (SSP), Security Assessment Report (SAR), and Plan of Action and Milestones (POA&M) to reflect these impacts and any necessary remediation.
Once the security impact of a change is determined by the change control board, it is crucial to update the relevant security documentation. This includes the System Security Plan (SSP) to reflect the new system state, the Security Assessment Report (SAR) if a reassessment was performed or its findings are altered, and the Plan of Action and Milestones (POA&M) to address any new or changed vulnerabilities or control deficiencies arising from the change.
Assessing a subset of controls typically happens before or as part of determining the security impact, not necessarily after the impact has already been determined by the board.
Preparing the SAR documenting issues, findings, and recommendations is usually done after a security assessment has been conducted, which might be part of determining the impact but not the direct next step after the impact is known and decided upon by the board.
Preparing POA&Ms is based on assessment findings, similar to the SAR, and while POA&Ms are updated after a change, this choice is less comprehensive than updating all relevant documents.
Concept tested: Post-change management in RMF
Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-37r2.pdf
Topics
Community Discussion
No community discussion yet for this question.