CGRC · Question #613
What is the first step in the process of implementing an Information Security Continuous Monitoring (ISCM)? Response:
The correct answer is A. Define an ISCM strategy. The first step in implementing an Information Security Continuous Monitoring (ISCM) program is to define a comprehensive strategy. This foundational step establishes the scope, objectives, and policies for ongoing security monitoring activities.
Question
What is the first step in the process of implementing an Information Security Continuous Monitoring (ISCM)? Response:
Options
- ADefine an ISCM strategy
- BEstablish an ISCM program
- CAnalyze data and report findings
- DImplement an ISCM program
How the community answered
(19 responses)- A89% (17)
- C5% (1)
- D5% (1)
Why each option
The first step in implementing an Information Security Continuous Monitoring (ISCM) program is to define a comprehensive strategy. This foundational step establishes the scope, objectives, and policies for ongoing security monitoring activities.
Defining an ISCM strategy is the initial and foundational step in the continuous monitoring process, establishing the scope, policies, and priorities before any implementation or data analysis can occur. This strategy guides the entire ISCM program, ensuring it meets organizational needs and regulatory requirements.
Establishing an ISCM program involves setting up the infrastructure and processes, which occurs after the strategy has been defined.
Analyzing data and reporting findings are later steps in the ISCM process, occurring after data collection and implementation of the monitoring tools.
Implementing an ISCM program involves putting the strategy into action, which logically follows the definition of the strategy itself.
Concept tested: NIST ISCM process steps
Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-137.pdf
Topics
Community Discussion
No community discussion yet for this question.