nerdexam
(ISC)2

CGRC · Question #54

Which of the following BEST describes the objective of a Security Assessment Plan? Response:

The correct answer is A. It provides a detailed roadmap for how the assessment will be conducted. A Security Assessment Plan serves as a detailed roadmap that outlines how an assessment will be executed. Its objective is to provide a structured guide for the assessment process, ensuring consistency and thoroughness.

Assessment/Audit of Security and Privacy Controls

Question

Which of the following BEST describes the objective of a Security Assessment Plan? Response:

Options

  • AIt provides a detailed roadmap for how the assessment will be conducted
  • BIt provides an assessment process for the integration of software and hardware
  • CIt describes how to verify the change control and Configuration Management (CM) practices
  • DIt ensures that changes made during system development are included in security assessments.

How the community answered

(38 responses)
  • A
    92% (35)
  • B
    5% (2)
  • D
    3% (1)

Why each option

A Security Assessment Plan serves as a detailed roadmap that outlines how an assessment will be executed. Its objective is to provide a structured guide for the assessment process, ensuring consistency and thoroughness.

AIt provides a detailed roadmap for how the assessment will be conductedCorrect

The objective of a Security Assessment Plan is to provide a comprehensive, detailed roadmap that specifies the procedures, scope, resources, and schedule for conducting a security assessment, guiding the assessors through the entire process.

BIt provides an assessment process for the integration of software and hardware

While an assessment may evaluate software and hardware integration, this is a specific activity within an assessment, not the overall objective of the plan itself.

CIt describes how to verify the change control and Configuration Management (CM) practices

Describing how to verify change control and Configuration Management (CM) practices is a specific part of the assessment methodology, not the overarching objective of the plan.

DIt ensures that changes made during system development are included in security assessments.

Ensuring changes are included in security assessments is an objective of configuration management and continuous monitoring, which an assessment plan facilitates but is not its primary goal.

Concept tested: Purpose of a Security Assessment Plan

Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53Ar5.pdf

Topics

#Security Assessment Plan#Security Assessment#Assessment Planning

Community Discussion

No community discussion yet for this question.

Full CGRC Practice