nerdexam
(ISC)2

CGRC · Question #550

What does the finding "other than satisfied" reflect in an assessment report? Response:

The correct answer is C. A lack of specified protection. A finding of 'other than satisfied' in an assessment report indicates a failure of a security control to meet its specified protection requirements. This implies that the control is not fully effective or implemented as required.

Assessment/Audit of Security and Privacy Controls

Question

What does the finding "other than satisfied" reflect in an assessment report? Response:

Options

  • AAn information security incident has occurred
  • BInformation types should be reevaluated
  • CA lack of specified protection
  • DThe contingency plan must be revised

How the community answered

(24 responses)
  • B
    4% (1)
  • C
    92% (22)
  • D
    4% (1)

Why each option

A finding of 'other than satisfied' in an assessment report indicates a failure of a security control to meet its specified protection requirements. This implies that the control is not fully effective or implemented as required.

AAn information security incident has occurred

While a lack of protection might contribute to an incident, 'other than satisfied' specifically describes the state of a control's effectiveness, not that an incident has occurred.

BInformation types should be reevaluated

Reevaluating information types, such as their categorization, is a separate activity from assessing the effectiveness of implemented security controls.

CA lack of specified protectionCorrect

When a security control is found to be 'other than satisfied' in an assessment report, it directly reflects a lack of specified protection; meaning the control is not adequately providing the expected security function. This finding indicates that the control may be partially implemented, ineffective, or completely missing, thereby failing to meet the established security objectives or requirements. It signals a deficiency in the system's security posture that needs to be addressed.

DThe contingency plan must be revised

Revising a contingency plan might be a remediation action for certain control deficiencies, but the finding 'other than satisfied' itself does not directly reflect the need for a plan revision.

Concept tested: Security assessment report findings

Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53Ar5.pdf

Topics

#Assessment findings#Control effectiveness#Security control deficiencies#Assessment reporting

Community Discussion

No community discussion yet for this question.

Full CGRC Practice