CGRC · Question #526
An initial remediation action was taken by the information system owner (ISO) based on findings from the security assessment report (SAR). What is the next appropriate step based on the Risk…
The correct answer is B. Include the remediation action taken by information system owner as an addendum to the SAR. Following initial remediation, the next appropriate step in the Risk Management Framework is to document the actions taken as an addendum to the Security Assessment Report (SAR) to provide a complete and updated record of the system's security posture.
Question
An initial remediation action was taken by the information system owner (ISO) based on findings from the security assessment report (SAR). What is the next appropriate step based on the Risk Management Framework (RMF)? Response:
Options
- AISO documents the remedial action in the security plan.
- BInclude the remediation action taken by information system owner as an addendum to the SAR.
- CInformation system security officer (ISSO) documents the remediation action and informs the ISO.
- DRemedial action taken is sent for review to the ISSO.
How the community answered
(25 responses)- A8% (2)
- B72% (18)
- C4% (1)
- D16% (4)
Why each option
Following initial remediation, the next appropriate step in the Risk Management Framework is to document the actions taken as an addendum to the Security Assessment Report (SAR) to provide a complete and updated record of the system's security posture.
While documentation is important, simply adding remediation details to the security plan is not the most direct or appropriate next step for formally updating assessment findings within the RMF process.
In the NIST RMF, after remediation actions are taken based on the Security Assessment Report (SAR) findings, these actions and their outcomes should be officially documented. Including them as an addendum to the SAR or updating the SAR itself ensures that the assessment documentation remains current and reflects the system's actual security posture post-remediation, which is crucial for subsequent authorization decisions.
The ISSO plays a role, but the primary action described is the documentation of the remediation in the context of the SAR, which is a formal record, not just internal communication.
Sending for review to the ISSO is part of the process, but the formal documentation of the remediation as an addendum to the SAR is the specific record-keeping outcome needed.
Concept tested: RMF post-assessment and remediation documentation
Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-37r2.pdf
Topics
Community Discussion
No community discussion yet for this question.