CGRC · Question #547
Another term used to refer to a Security Controls Assessment or security review; is? Response:
The correct answer is A. Security Test & Evaluation (ST&E). Security Test & Evaluation (ST&E) is an overarching term often used to describe the process of assessing and reviewing the effectiveness of an information system's security controls. It encompasses both technical testing and evaluation activities.
Question
Another term used to refer to a Security Controls Assessment or security review; is? Response:
Options
- ASecurity Test & Evaluation (ST&E)
- BSecurity Test (ST)
- CEvaluation
- DSecurity Control
How the community answered
(49 responses)- A86% (42)
- B2% (1)
- C8% (4)
- D4% (2)
Why each option
Security Test & Evaluation (ST&E) is an overarching term often used to describe the process of assessing and reviewing the effectiveness of an information system's security controls. It encompasses both technical testing and evaluation activities.
Security Test & Evaluation (ST&E) is a comprehensive process that involves systematically examining an information system's security controls to ensure they are implemented correctly, operating as intended, and achieving the desired security outcomes. This term is widely used to refer to activities such as vulnerability scanning, penetration testing, and security control assessments, all aimed at evaluating the overall security posture and compliance. ST&E provides management with critical information for making risk-based decisions on system authorization.
'Security Test' is generally considered a component of ST&E, not the comprehensive term for a full security controls assessment or review.
'Evaluation' is a generic term that lacks the specific context of security controls assessment in the IT domain.
'Security Control' refers to the safeguard itself, not the process of assessing or reviewing it.
Concept tested: Security controls assessment terminology
Topics
Community Discussion
No community discussion yet for this question.