nerdexam
(ISC)2

CGRC · Question #527

What assessment procedure is designed to work with and complement the assessment procedures to contribute to the grounds for confidence in the effectiveness of the security controls employed in the in

The correct answer is A. Extended. Extended assessment procedures are designed to work in conjunction with and complement standard assessment procedures, thereby increasing the confidence in the effectiveness of an information system's security controls.

Assessment/Audit of Security and Privacy Controls

Question

What assessment procedure is designed to work with and complement the assessment procedures to contribute to the grounds for confidence in the effectiveness of the security controls employed in the information system? Response:

Options

  • AExtended
  • BSubordinate
  • CBased
  • DCross control

How the community answered

(24 responses)
  • A
    88% (21)
  • B
    4% (1)
  • D
    8% (2)

Why each option

Extended assessment procedures are designed to work in conjunction with and complement standard assessment procedures, thereby increasing the confidence in the effectiveness of an information system's security controls.

AExtendedCorrect

Extended assessment procedures are specialized, more in-depth assessment techniques that build upon basic assessment procedures to provide additional evidence and higher assurance regarding the effectiveness of security controls. They are used to address specific high-impact controls, unique system characteristics, or areas requiring greater scrutiny, thus complementing and strengthening the overall assessment.

BSubordinate

'Subordinate' procedures would imply a lower level or less comprehensive assessment, which does not fit the description of contributing to increased confidence in effectiveness.

CBased

'Based' is too vague and does not describe a type of assessment procedure designed to complement others.

DCross control

'Cross control' could refer to dependencies between controls but is not a standard term for a complementary assessment procedure in this context.

Concept tested: Types of security control assessment procedures (NIST)

Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53Ar4.pdf

Topics

#Assessment procedures#Extended assessment#Security control effectiveness#Confidence

Community Discussion

No community discussion yet for this question.

Full CGRC Practice