nerdexam
(ISC)2

CGRC · Question #562

Which of the following is principally used to verify that Information Systems (IS) are meeting their stated security goals and objectives? Response:

The correct answer is A. System Plan (SP). A System Plan, often a System Security Plan, is the primary document used to outline an information system's security controls and objectives, serving as the basis for verification that these goals are met.

Assessment/Audit of Security and Privacy Controls

Question

Which of the following is principally used to verify that Information Systems (IS) are meeting their stated security goals and objectives? Response:

Options

  • ASystem Plan (SP)
  • BRequirements Traceability Matrix (RTM)
  • CRisk Assessment (RA)
  • DSecurity Control Assessor

How the community answered

(31 responses)
  • A
    90% (28)
  • B
    3% (1)
  • D
    6% (2)

Why each option

A System Plan, often a System Security Plan, is the primary document used to outline an information system's security controls and objectives, serving as the basis for verification that these goals are met.

ASystem Plan (SP)Correct

A System Plan, particularly a System Security Plan (SSP), provides a comprehensive blueprint of an information system's security controls, policies, and procedures. This document details how the system will achieve its security goals and objectives, making it the foundational reference against which all security verifications and assessments are performed to ensure compliance and effectiveness.

BRequirements Traceability Matrix (RTM)

A Requirements Traceability Matrix (RTM) maps requirements to testing and development stages, primarily used for tracking completeness rather than verifying an operational IS against its security goals.

CRisk Assessment (RA)

A Risk Assessment (RA) identifies, analyzes, and evaluates potential risks, informing security decisions but not serving as the principal document for verifying goal achievement.

DSecurity Control Assessor

A Security Control Assessor is a role responsible for performing security assessments and verification, not a document or process used for verification itself.

Concept tested: System Security Plan purpose

Source: https://csrc.nist.gov/publications/detail/sp/800-18/rev-1/final

Topics

#System Security Plan#Security Goals#Verification#Security Controls

Community Discussion

No community discussion yet for this question.

Full CGRC Practice