CGRC · Question #50
What is the comprehensive assessment of the management, operational, and technical security controls in an information system, made in support of security accreditation, to determine the extent to…
The correct answer is A. Certification. Certification is a thorough assessment of an information system's security controls-management, operational, and technical-to confirm their correct implementation, intended operation, and effectiveness in meeting security requirements. This assessment provides critical findings…
Question
What is the comprehensive assessment of the management, operational, and technical security controls in an information system, made in support of security accreditation, to determine the extent to which the controls are implemented correctly, operating as intended, and producing the desired outcome with respect to meeting the security requirements for the system. Response:
Options
- ACertification
- BExamination
- COperation
- DInformation
How the community answered
(31 responses)- A94% (29)
- C3% (1)
- D3% (1)
Why each option
Certification is a thorough assessment of an information system's security controls-management, operational, and technical-to confirm their correct implementation, intended operation, and effectiveness in meeting security requirements. This assessment provides critical findings that underpin the accreditation decision for system operation.
Certification is the comprehensive assessment of an information system's security controls to determine the extent to which they are implemented correctly, operating as intended, and producing the desired outcomes with respect to meeting security requirements. This process provides the technical and procedural findings that support the accreditation decision.
Examination is a general term for an inspection or analysis, but it is not the specific, formal term used in IT security for a comprehensive control assessment supporting accreditation.
Operation refers to the ongoing functioning of a system, not a specific assessment process of its security controls.
Information is a broad term and does not describe the specific process of assessing security controls for a system.
Concept tested: Definition of Certification (Security)
Source: https://csrc.nist.gov/glossary/term/certification
Topics
Community Discussion
No community discussion yet for this question.