nerdexam
(ISC)2

CGRC · Question #493

An effective security control monitoring strategy for an information system includes Response:

The correct answer is B. active involvement by authorizing officials in the ongoing management of information system-. An effective security control monitoring strategy for an information system requires active involvement from authorizing officials to ensure continuous oversight and management of the system's security posture. This continuous engagement is crucial for maintaining ongoing…

Compliance Maintenance

Question

An effective security control monitoring strategy for an information system includes Response:

Options

  • Amonitoring the security controls of interconnecting information systems outside the authorization
  • Bactive involvement by authorizing officials in the ongoing management of information system-
  • Cthe annual assessment of all security controls in the information system.
  • Dall controls listed in NIST SP 800-53, Revision 3.

How the community answered

(29 responses)
  • A
    3% (1)
  • B
    93% (27)
  • D
    3% (1)

Why each option

An effective security control monitoring strategy for an information system requires active involvement from authorizing officials to ensure continuous oversight and management of the system's security posture. This continuous engagement is crucial for maintaining ongoing authorization and adapting to evolving threats.

Amonitoring the security controls of interconnecting information systems outside the authorization

Monitoring interconnecting systems' controls is important, but doing so outside the scope of authorization implies a lack of proper governance and agreements.

Bactive involvement by authorizing officials in the ongoing management of information system-Correct

Effective security control monitoring, as part of the NIST Risk Management Framework (RMF) Step 6 (Monitor), emphasizes the ongoing involvement of the Authorizing Official (AO) in the management of the information system's security. This active involvement ensures that the system's security posture is continuously assessed and maintained, aligning with the concept of ongoing authorization.

Cthe annual assessment of all security controls in the information system.

Annual assessment of all controls is a periodic activity, but an effective monitoring strategy goes beyond just annual assessments to include continuous and near real-time monitoring.

Dall controls listed in NIST SP 800-53, Revision 3.

While NIST SP 800-53 controls are foundational, simply listing all controls from an outdated revision (Rev 3) does not define an effective monitoring strategy; the focus is on implementation and ongoing assessment.

Concept tested: RMF Security Control Monitoring, Authorizing Official role

Source: https://csrc.nist.gov/publications/detail/sp/800-37/rev-2/final

Topics

#Security Control Monitoring#Authorizing Officials#Ongoing Management#Continuous Monitoring

Community Discussion

No community discussion yet for this question.

Full CGRC Practice