CGRC · Question #49
The security control assessor for Colvine Tech will be conducting a comprehensive level assessment on an information system at Colvine Tech. Which controls must be assessed separately, not by the…
The correct answer is A. Common Controls. Common controls are security controls that are designed to be inherited by multiple information systems and are typically assessed independently by a common control provider. Therefore, the individual assessor for a specific system only confirms the inheritance and ongoing…
Question
The security control assessor for Colvine Tech will be conducting a comprehensive level assessment on an information system at Colvine Tech. Which controls must be assessed separately, not by the assessor for colvine Tech? Response:
Options
- ACommon Controls
- BManagement controls
- CFailed controls
- DAlternative controls
How the community answered
(26 responses)- A92% (24)
- C4% (1)
- D4% (1)
Why each option
Common controls are security controls that are designed to be inherited by multiple information systems and are typically assessed independently by a common control provider. Therefore, the individual assessor for a specific system only confirms the inheritance and ongoing effectiveness of these shared controls, rather than conducting a full re-assessment.
Common Controls are implemented once and inherited by multiple information systems, typically provided by an organizational entity (the common control provider). The assessment of these common controls is performed by an assessor for the common control provider, and the inheriting system's assessor does not re-assess these controls, but rather confirms their inheritance and effectiveness.
Management controls, like other control types (operational, technical), are part of the system's overall control set and would be assessed by the system's assessor.
Failed controls indicate deficiencies within the system and would certainly be a focus of the system's assessor for remediation, not assessed separately.
Alternative controls (or compensating controls) are implemented by the system and would be assessed by the system's assessor to determine their effectiveness.
Concept tested: Common controls assessment responsibility
Source: https://csrc.nist.gov/glossary/term/common-control
Topics
Community Discussion
No community discussion yet for this question.