CGRC · Question #493
An effective security control monitoring strategy for an information system includes Response:
The correct answer is B. active involvement by authorizing officials in the ongoing management of information system-. An effective security control monitoring strategy for an information system requires active involvement from authorizing officials to ensure continuous oversight and management of the system's security posture. This continuous engagement is crucial for maintaining ongoing…
Question
An effective security control monitoring strategy for an information system includes Response:
Options
- Amonitoring the security controls of interconnecting information systems outside the authorization
- Bactive involvement by authorizing officials in the ongoing management of information system-
- Cthe annual assessment of all security controls in the information system.
- Dall controls listed in NIST SP 800-53, Revision 3.
How the community answered
(29 responses)- A3% (1)
- B93% (27)
- D3% (1)
Why each option
An effective security control monitoring strategy for an information system requires active involvement from authorizing officials to ensure continuous oversight and management of the system's security posture. This continuous engagement is crucial for maintaining ongoing authorization and adapting to evolving threats.
Monitoring interconnecting systems' controls is important, but doing so outside the scope of authorization implies a lack of proper governance and agreements.
Effective security control monitoring, as part of the NIST Risk Management Framework (RMF) Step 6 (Monitor), emphasizes the ongoing involvement of the Authorizing Official (AO) in the management of the information system's security. This active involvement ensures that the system's security posture is continuously assessed and maintained, aligning with the concept of ongoing authorization.
Annual assessment of all controls is a periodic activity, but an effective monitoring strategy goes beyond just annual assessments to include continuous and near real-time monitoring.
While NIST SP 800-53 controls are foundational, simply listing all controls from an outdated revision (Rev 3) does not define an effective monitoring strategy; the focus is on implementation and ongoing assessment.
Concept tested: RMF Security Control Monitoring, Authorizing Official role
Source: https://csrc.nist.gov/publications/detail/sp/800-37/rev-2/final
Topics
Community Discussion
No community discussion yet for this question.