nerdexam
(ISC)2

CGRC · Question #591

After a monthly change control board meeting at which the team determined the security impact of proposed changes to an application, what would be the team's next action? Response:

The correct answer is C. Update the security plan, security assessment report, and plan of action and milestones based on. After a change control board determines the security impact of proposed changes, the immediate next step is to update all relevant RMF documentation, including the security plan, security assessment report, and plan of action and milestones, to reflect these changes and their…

Compliance Maintenance

Question

After a monthly change control board meeting at which the team determined the security impact of proposed changes to an application, what would be the team's next action? Response:

Options

  • APrepare the plan of action and milestones based on the findings and recommendations of the
  • BPrepare the security assessment report documenting the issues, findings, and recommendations
  • CUpdate the security plan, security assessment report, and plan of action and milestones based on
  • DAssess a selected subset of the security controls employed within and inherited by the application

How the community answered

(25 responses)
  • A
    4% (1)
  • B
    8% (2)
  • C
    72% (18)
  • D
    16% (4)

Why each option

After a change control board determines the security impact of proposed changes, the immediate next step is to update all relevant RMF documentation, including the security plan, security assessment report, and plan of action and milestones, to reflect these changes and their security implications.

APrepare the plan of action and milestones based on the findings and recommendations of the

Preparing only the POA&M is incomplete; the security plan and SAR also need updates to reflect the change's impact on the overall security posture and assessment.

BPrepare the security assessment report documenting the issues, findings, and recommendations

Preparing only the security assessment report is incomplete; the security plan and POA&M also need updates to reflect the change's impact on planned controls and identified mitigations.

CUpdate the security plan, security assessment report, and plan of action and milestones based onCorrect

After determining the security impact of proposed changes in a change control board meeting, the critical next step is to update the system's security documentation. This includes revising the security plan to reflect the new configuration or operational state, updating the security assessment report with any new findings or risks, and modifying the plan of action and milestones (POA&M) to address any newly identified vulnerabilities or needed mitigations resulting from the changes. This ensures all documentation remains current and accurate for ongoing risk management.

DAssess a selected subset of the security controls employed within and inherited by the application

Assessing a subset of security controls is typically part of the 'Assess' step or ongoing monitoring, which would occur before or during the impact analysis, but not as the immediate next step after the change control board has determined the impact and needs to document it.

Concept tested: RMF monitoring and change management documentation

Source: https://csrc.nist.gov/publications/detail/sp/800-37/rev-2/final

Topics

#Change Management#Continuous Monitoring#RMF Documentation#System Maintenance

Community Discussion

No community discussion yet for this question.

Full CGRC Practice