nerdexam
(ISC)2

CGRC · Question #486

The change control board team at Colvine Tech has determined the security impact of proposed changes to an application, what would be the team's next action? Response:

The correct answer is A. Update the SSP, SAR, and POA&Ms based on the results of the change control board's security. After a change control board determines the security impact of proposed changes, the logical next step is to update official documentation like the System Security Plan (SSP), Security Assessment Report (SAR), and Plan of Action and Milestones (POA&M) to reflect these impacts…

Compliance Maintenance

Question

The change control board team at Colvine Tech has determined the security impact of proposed changes to an application, what would be the team's next action? Response:

Options

  • AUpdate the SSP, SAR, and POA&Ms based on the results of the change control board's security
  • BAssess a selected subset of the security controls employed within and inherited by the application
  • CPrepare the SAR documenting the issues, findings, and recommendations from the security
  • DPrepare the POA&Ms based on the findings and recommendations of the security assessment

How the community answered

(25 responses)
  • A
    72% (18)
  • B
    4% (1)
  • C
    8% (2)
  • D
    16% (4)

Why each option

After a change control board determines the security impact of proposed changes, the logical next step is to update official documentation like the System Security Plan (SSP), Security Assessment Report (SAR), and Plan of Action and Milestones (POA&M) to reflect these impacts and any necessary remediation.

AUpdate the SSP, SAR, and POA&Ms based on the results of the change control board's securityCorrect

Once the security impact of a change is determined by the change control board, it is crucial to update the relevant security documentation. This includes the System Security Plan (SSP) to reflect the new system state, the Security Assessment Report (SAR) if a reassessment was performed or its findings are altered, and the Plan of Action and Milestones (POA&M) to address any new or changed vulnerabilities or control deficiencies arising from the change.

BAssess a selected subset of the security controls employed within and inherited by the application

Assessing a subset of controls typically happens before or as part of determining the security impact, not necessarily after the impact has already been determined by the board.

CPrepare the SAR documenting the issues, findings, and recommendations from the security

Preparing the SAR documenting issues, findings, and recommendations is usually done after a security assessment has been conducted, which might be part of determining the impact but not the direct next step after the impact is known and decided upon by the board.

DPrepare the POA&Ms based on the findings and recommendations of the security assessment

Preparing POA&Ms is based on assessment findings, similar to the SAR, and while POA&Ms are updated after a change, this choice is less comprehensive than updating all relevant documents.

Concept tested: Post-change management in RMF

Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-37r2.pdf

Topics

#Change Management#System Security Plan (SSP)#Security Documentation#Continuous Monitoring

Community Discussion

No community discussion yet for this question.

Full CGRC Practice