nerdexam
(ISC)2

CGRC · Question #633

An effective continuous monitoring program can be used to Response:

The correct answer is D. support the Federal Information Security Management Act (FISMA) requirement for annual. An effective continuous monitoring program is crucial for maintaining ongoing situational awareness of an organization's security posture and directly supports the annual reporting requirements mandated by FISMA.

Compliance Maintenance

Question

An effective continuous monitoring program can be used to Response:

Options

  • Ameet the Federal Information Processing Standard (FIPS) Publication 200 requirement for monthly
  • Bmeet an organization's requirement for periodic information assurance training of all computer
  • Creplace information system security audit logs.
  • Dsupport the Federal Information Security Management Act (FISMA) requirement for annual

How the community answered

(64 responses)
  • A
    3% (2)
  • B
    13% (8)
  • C
    5% (3)
  • D
    80% (51)

Why each option

An effective continuous monitoring program is crucial for maintaining ongoing situational awareness of an organization's security posture and directly supports the annual reporting requirements mandated by FISMA.

Ameet the Federal Information Processing Standard (FIPS) Publication 200 requirement for monthly

FIPS 200 outlines minimum security requirements for federal information systems but does not specifically mandate a monthly requirement that continuous monitoring fulfills in this manner.

Bmeet an organization's requirement for periodic information assurance training of all computer

Continuous monitoring programs focus on security posture and control effectiveness, not on fulfilling periodic information assurance training requirements for personnel.

Creplace information system security audit logs.

Continuous monitoring programs utilize audit logs as input but do not replace them; logs are a fundamental component of monitoring, not superseded by it.

Dsupport the Federal Information Security Management Act (FISMA) requirement for annualCorrect

The Federal Information Security Management Act (FISMA) mandates that federal agencies conduct annual reviews of their information security programs and report their findings. Continuous monitoring provides the real-time and ongoing data necessary to assess the effectiveness of security controls and manage risk, directly feeding into these annual FISMA reporting obligations.

Concept tested: Purpose of continuous monitoring in compliance

Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-137.pdf

Topics

#continuous monitoring#FISMA#compliance#regulatory reporting

Community Discussion

No community discussion yet for this question.

Full CGRC Practice