nerdexam
(ISC)2

CGRC · Question #50

What is the comprehensive assessment of the management, operational, and technical security controls in an information system, made in support of security accreditation, to determine the extent to…

The correct answer is A. Certification. Certification is a thorough assessment of an information system's security controls-management, operational, and technical-to confirm their correct implementation, intended operation, and effectiveness in meeting security requirements. This assessment provides critical findings…

Assessment/Audit of Security and Privacy Controls

Question

What is the comprehensive assessment of the management, operational, and technical security controls in an information system, made in support of security accreditation, to determine the extent to which the controls are implemented correctly, operating as intended, and producing the desired outcome with respect to meeting the security requirements for the system. Response:

Options

  • ACertification
  • BExamination
  • COperation
  • DInformation

How the community answered

(31 responses)
  • A
    94% (29)
  • C
    3% (1)
  • D
    3% (1)

Why each option

Certification is a thorough assessment of an information system's security controls-management, operational, and technical-to confirm their correct implementation, intended operation, and effectiveness in meeting security requirements. This assessment provides critical findings that underpin the accreditation decision for system operation.

ACertificationCorrect

Certification is the comprehensive assessment of an information system's security controls to determine the extent to which they are implemented correctly, operating as intended, and producing the desired outcomes with respect to meeting security requirements. This process provides the technical and procedural findings that support the accreditation decision.

BExamination

Examination is a general term for an inspection or analysis, but it is not the specific, formal term used in IT security for a comprehensive control assessment supporting accreditation.

COperation

Operation refers to the ongoing functioning of a system, not a specific assessment process of its security controls.

DInformation

Information is a broad term and does not describe the specific process of assessing security controls for a system.

Concept tested: Definition of Certification (Security)

Source: https://csrc.nist.gov/glossary/term/certification

Topics

#Certification#Security Controls Assessment#Accreditation Support#RMF

Community Discussion

No community discussion yet for this question.

Full CGRC Practice