nerdexam
(ISC)2

CGRC · Question #613

What is the first step in the process of implementing an Information Security Continuous Monitoring (ISCM)? Response:

The correct answer is A. Define an ISCM strategy. The first step in implementing an Information Security Continuous Monitoring (ISCM) program is to define a comprehensive strategy. This foundational step establishes the scope, objectives, and policies for ongoing security monitoring activities.

Security and Privacy Governance, Risk Management, and Compliance Program

Question

What is the first step in the process of implementing an Information Security Continuous Monitoring (ISCM)? Response:

Options

  • ADefine an ISCM strategy
  • BEstablish an ISCM program
  • CAnalyze data and report findings
  • DImplement an ISCM program

How the community answered

(19 responses)
  • A
    89% (17)
  • C
    5% (1)
  • D
    5% (1)

Why each option

The first step in implementing an Information Security Continuous Monitoring (ISCM) program is to define a comprehensive strategy. This foundational step establishes the scope, objectives, and policies for ongoing security monitoring activities.

ADefine an ISCM strategyCorrect

Defining an ISCM strategy is the initial and foundational step in the continuous monitoring process, establishing the scope, policies, and priorities before any implementation or data analysis can occur. This strategy guides the entire ISCM program, ensuring it meets organizational needs and regulatory requirements.

BEstablish an ISCM program

Establishing an ISCM program involves setting up the infrastructure and processes, which occurs after the strategy has been defined.

CAnalyze data and report findings

Analyzing data and reporting findings are later steps in the ISCM process, occurring after data collection and implementation of the monitoring tools.

DImplement an ISCM program

Implementing an ISCM program involves putting the strategy into action, which logically follows the definition of the strategy itself.

Concept tested: NIST ISCM process steps

Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-137.pdf

Topics

#Information Security Continuous Monitoring (ISCM)#ISCM strategy#Program implementation#Security governance

Community Discussion

No community discussion yet for this question.

Full CGRC Practice