nerdexam
(ISC)2

CGRC · Question #528

What is the purpose of security impact analysis? Response:

The correct answer is A. To determine the extent to which proposed or actual changes to the system or its environment of. The purpose of security impact analysis is to evaluate how proposed or actual changes to an information system or its operating environment might affect the system's security posture and the effectiveness of its security controls.

Compliance Maintenance

Question

What is the purpose of security impact analysis? Response:

Options

  • ATo determine the extent to which proposed or actual changes to the system or its environment of
  • BTo determine the level of impact of the violation of the confidentiality of PII
  • CTo determine if the information system processes PII
  • DNon of the above

How the community answered

(35 responses)
  • A
    94% (33)
  • C
    3% (1)
  • D
    3% (1)

Why each option

The purpose of security impact analysis is to evaluate how proposed or actual changes to an information system or its operating environment might affect the system's security posture and the effectiveness of its security controls.

ATo determine the extent to which proposed or actual changes to the system or its environment ofCorrect

Security impact analysis is a critical component of change management, used to assess the potential security risks and implications that arise from modifications to a system or its environment. This analysis helps ensure that changes do not introduce new vulnerabilities or degrade existing security controls, thereby maintaining the overall security posture.

BTo determine the level of impact of the violation of the confidentiality of PII

While security impact analysis can be performed for a breach, its primary purpose in a proactive sense is to analyze changes, not specifically the impact of a PII confidentiality violation, although that might be an outcome of a poorly managed change.

CTo determine if the information system processes PII

Determining if a system processes PII is part of system categorization or data inventory, not the purpose of security impact analysis.

DNon of the above

Choice A accurately describes the purpose of security impact analysis, making 'None of the above' incorrect.

Concept tested: Purpose of security impact analysis (change management)

Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-128.pdf

Topics

#Security Impact Analysis#Change Management#Compliance Maintenance

Community Discussion

No community discussion yet for this question.

Full CGRC Practice