CGRC · Question #54
Which of the following BEST describes the objective of a Security Assessment Plan? Response:
The correct answer is A. It provides a detailed roadmap for how the assessment will be conducted. A Security Assessment Plan serves as a detailed roadmap that outlines how an assessment will be executed. Its objective is to provide a structured guide for the assessment process, ensuring consistency and thoroughness.
Question
Which of the following BEST describes the objective of a Security Assessment Plan? Response:
Options
- AIt provides a detailed roadmap for how the assessment will be conducted
- BIt provides an assessment process for the integration of software and hardware
- CIt describes how to verify the change control and Configuration Management (CM) practices
- DIt ensures that changes made during system development are included in security assessments.
How the community answered
(38 responses)- A92% (35)
- B5% (2)
- D3% (1)
Why each option
A Security Assessment Plan serves as a detailed roadmap that outlines how an assessment will be executed. Its objective is to provide a structured guide for the assessment process, ensuring consistency and thoroughness.
The objective of a Security Assessment Plan is to provide a comprehensive, detailed roadmap that specifies the procedures, scope, resources, and schedule for conducting a security assessment, guiding the assessors through the entire process.
While an assessment may evaluate software and hardware integration, this is a specific activity within an assessment, not the overall objective of the plan itself.
Describing how to verify change control and Configuration Management (CM) practices is a specific part of the assessment methodology, not the overarching objective of the plan.
Ensuring changes are included in security assessments is an objective of configuration management and continuous monitoring, which an assessment plan facilitates but is not its primary goal.
Concept tested: Purpose of a Security Assessment Plan
Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53Ar5.pdf
Topics
Community Discussion
No community discussion yet for this question.