CGRC · Question #605
The Information system owner should strive to test every control at least every ___ years & most critical controls continuously. Response:
The correct answer is A. Three. Information system owners are advised to test every security control at least every three years, with a focus on continuous monitoring for critical controls. This ensures ongoing effectiveness and adherence to security requirements.
Question
The Information system owner should strive to test every control at least every ___ years & most critical controls continuously. Response:
Options
- AThree
- BTwo
- CFour
- DSix
How the community answered
(54 responses)- A89% (48)
- B4% (2)
- C2% (1)
- D6% (3)
Why each option
Information system owners are advised to test every security control at least every three years, with a focus on continuous monitoring for critical controls. This ensures ongoing effectiveness and adherence to security requirements.
Industry best practices and frameworks, such as NIST SP 800-53A and common certification guidelines, recommend that all security controls should be assessed or tested at least every three years, coinciding with reauthorization cycles. Critical controls, however, require continuous monitoring for optimal security posture.
While some organizations might test more frequently, 'two years' is not the universally recommended minimum for every control as a general guideline.
Testing every four years would be less frequent than the recommended standard and might leave systems vulnerable for too long between assessments.
Testing every six years is far too infrequent for maintaining a robust security posture and would not meet common compliance or best practice standards.
Concept tested: Security control assessment frequency
Source: https://csrc.nist.gov/publications/detail/sp/800-37/rev-2/final
Topics
Community Discussion
No community discussion yet for this question.