CGRC · Question #51
A security assessment plan comprises of all of the following except one Response:
The correct answer is C. Recommendations for remediation. A security assessment plan outlines how an assessment will be conducted, including its scope, methodology, and rules of engagement. Recommendations for remediation are outputs of the assessment, not components of the plan itself.
Question
A security assessment plan comprises of all of the following except one Response:
Options
- AScope
- BMethodology
- CRecommendations for remediation
- DRules of engagement
How the community answered
(35 responses)- A3% (1)
- B6% (2)
- C89% (31)
- D3% (1)
Why each option
A security assessment plan outlines how an assessment will be conducted, including its scope, methodology, and rules of engagement. Recommendations for remediation are outputs of the assessment, not components of the plan itself.
Scope is a fundamental component of an assessment plan, defining what systems, data, and processes will be included or excluded from the evaluation.
Methodology outlines the specific approaches, tools, and techniques that will be used during the security assessment to achieve its objectives.
Recommendations for remediation are outputs generated after a security assessment identifies findings and analyzes their implications, rather than being a pre-defined component of the plan that describes how the assessment will be performed.
Rules of engagement specify the boundaries, communication protocols, and acceptable activities for the assessment team during the execution phase.
Concept tested: Security assessment plan components
Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53Ar5.pdf
Topics
Community Discussion
No community discussion yet for this question.