CGRC · Question #540
Which of the following NIST documents includes components for penetration testing? Response:
The correct answer is D. NIST SP 800-30. NIST Special Publication 800-30, "Guide for Conducting Risk Assessments," includes components for penetration testing by identifying it as a crucial method for discovering vulnerabilities. The document explains how information gathered from penetration tests serves as critical…
Question
Which of the following NIST documents includes components for penetration testing? Response:
Options
- ANIST SP 800-53
- BNIST SP 800-26
- CNIST SP 800-37
- DNIST SP 800-30
How the community answered
(39 responses)- A3% (1)
- C5% (2)
- D92% (36)
Why each option
NIST Special Publication 800-30, "Guide for Conducting Risk Assessments," includes components for penetration testing by identifying it as a crucial method for discovering vulnerabilities. The document explains how information gathered from penetration tests serves as critical input for a comprehensive risk assessment, thus integrating it into the risk management process.
NIST SP 800-53 defines "Penetration Testing" as a security control (CA-8), but SP 800-30 guides the use of such testing within risk assessment.
NIST SP 800-26, "Security Self-Assessment Guide for Information Technology Systems," is an older, withdrawn document that does not specifically detail components for penetration testing in the context of current frameworks.
NIST SP 800-37, the Risk Management Framework guide, refers to penetration testing as an assessment method, but SP 800-30 focuses on its role in identifying risks.
NIST SP 800-30, "Guide for Conducting Risk Assessments," explicitly recognizes penetration testing as a method for identifying vulnerabilities, which provides essential input for conducting effective risk assessments.
Concept tested: NIST documents and penetration testing's role
Source: https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-30r1.pdf
Topics
Community Discussion
No community discussion yet for this question.