nerdexam
(ISC)2

CGRC · Question #49

The security control assessor for Colvine Tech will be conducting a comprehensive level assessment on an information system at Colvine Tech. Which controls must be assessed separately, not by the…

The correct answer is A. Common Controls. Common controls are security controls that are designed to be inherited by multiple information systems and are typically assessed independently by a common control provider. Therefore, the individual assessor for a specific system only confirms the inheritance and ongoing…

Assessment/Audit of Security and Privacy Controls

Question

The security control assessor for Colvine Tech will be conducting a comprehensive level assessment on an information system at Colvine Tech. Which controls must be assessed separately, not by the assessor for colvine Tech? Response:

Options

  • ACommon Controls
  • BManagement controls
  • CFailed controls
  • DAlternative controls

How the community answered

(26 responses)
  • A
    92% (24)
  • C
    4% (1)
  • D
    4% (1)

Why each option

Common controls are security controls that are designed to be inherited by multiple information systems and are typically assessed independently by a common control provider. Therefore, the individual assessor for a specific system only confirms the inheritance and ongoing effectiveness of these shared controls, rather than conducting a full re-assessment.

ACommon ControlsCorrect

Common Controls are implemented once and inherited by multiple information systems, typically provided by an organizational entity (the common control provider). The assessment of these common controls is performed by an assessor for the common control provider, and the inheriting system's assessor does not re-assess these controls, but rather confirms their inheritance and effectiveness.

BManagement controls

Management controls, like other control types (operational, technical), are part of the system's overall control set and would be assessed by the system's assessor.

CFailed controls

Failed controls indicate deficiencies within the system and would certainly be a focus of the system's assessor for remediation, not assessed separately.

DAlternative controls

Alternative controls (or compensating controls) are implemented by the system and would be assessed by the system's assessor to determine their effectiveness.

Concept tested: Common controls assessment responsibility

Source: https://csrc.nist.gov/glossary/term/common-control

Topics

#Common Controls#Security Control Assessment#Control Inheritance#RMF

Community Discussion

No community discussion yet for this question.

Full CGRC Practice