CGRC · Question #528
What is the purpose of security impact analysis? Response:
The correct answer is A. To determine the extent to which proposed or actual changes to the system or its environment of. The purpose of security impact analysis is to evaluate how proposed or actual changes to an information system or its operating environment might affect the system's security posture and the effectiveness of its security controls.
Question
What is the purpose of security impact analysis? Response:
Options
- ATo determine the extent to which proposed or actual changes to the system or its environment of
- BTo determine the level of impact of the violation of the confidentiality of PII
- CTo determine if the information system processes PII
- DNon of the above
How the community answered
(35 responses)- A94% (33)
- C3% (1)
- D3% (1)
Why each option
The purpose of security impact analysis is to evaluate how proposed or actual changes to an information system or its operating environment might affect the system's security posture and the effectiveness of its security controls.
Security impact analysis is a critical component of change management, used to assess the potential security risks and implications that arise from modifications to a system or its environment. This analysis helps ensure that changes do not introduce new vulnerabilities or degrade existing security controls, thereby maintaining the overall security posture.
While security impact analysis can be performed for a breach, its primary purpose in a proactive sense is to analyze changes, not specifically the impact of a PII confidentiality violation, although that might be an outcome of a poorly managed change.
Determining if a system processes PII is part of system categorization or data inventory, not the purpose of security impact analysis.
Choice A accurately describes the purpose of security impact analysis, making 'None of the above' incorrect.
Concept tested: Purpose of security impact analysis (change management)
Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-128.pdf
Topics
Community Discussion
No community discussion yet for this question.