nerdexam
(ISC)2

CGRC · Question #605

The Information system owner should strive to test every control at least every ___ years & most critical controls continuously. Response:

The correct answer is A. Three. Information system owners are advised to test every security control at least every three years, with a focus on continuous monitoring for critical controls. This ensures ongoing effectiveness and adherence to security requirements.

Assessment/Audit of Security and Privacy Controls

Question

The Information system owner should strive to test every control at least every ___ years & most critical controls continuously. Response:

Options

  • AThree
  • BTwo
  • CFour
  • DSix

How the community answered

(54 responses)
  • A
    89% (48)
  • B
    4% (2)
  • C
    2% (1)
  • D
    6% (3)

Why each option

Information system owners are advised to test every security control at least every three years, with a focus on continuous monitoring for critical controls. This ensures ongoing effectiveness and adherence to security requirements.

AThreeCorrect

Industry best practices and frameworks, such as NIST SP 800-53A and common certification guidelines, recommend that all security controls should be assessed or tested at least every three years, coinciding with reauthorization cycles. Critical controls, however, require continuous monitoring for optimal security posture.

BTwo

While some organizations might test more frequently, 'two years' is not the universally recommended minimum for every control as a general guideline.

CFour

Testing every four years would be less frequent than the recommended standard and might leave systems vulnerable for too long between assessments.

DSix

Testing every six years is far too infrequent for maintaining a robust security posture and would not meet common compliance or best practice standards.

Concept tested: Security control assessment frequency

Source: https://csrc.nist.gov/publications/detail/sp/800-37/rev-2/final

Topics

#Control testing frequency#Continuous monitoring#Control assessment#System owner responsibilities

Community Discussion

No community discussion yet for this question.

Full CGRC Practice