nerdexam
(ISC)2

CGRC · Question #649

Which of the following in an assessment plan protects the security control assessment team from liability should the security control assessment result in unforeseen damage? Response:

The correct answer is D. Rules of engagement. The Rules of Engagement (ROE) within an assessment plan are critical for protecting the security control assessment team from liability by clearly defining the scope, authorized activities, communication protocols, and acceptable risks. ROE establishes legal and ethical…

Assessment/Audit of Security and Privacy Controls

Question

Which of the following in an assessment plan protects the security control assessment team from liability should the security control assessment result in unforeseen damage? Response:

Options

  • ANon-invasive testing
  • BManual testing
  • CVulnerability scans
  • DRules of engagement

How the community answered

(32 responses)
  • A
    6% (2)
  • B
    3% (1)
  • C
    3% (1)
  • D
    88% (28)

Why each option

The Rules of Engagement (ROE) within an assessment plan are critical for protecting the security control assessment team from liability by clearly defining the scope, authorized activities, communication protocols, and acceptable risks. ROE establishes legal and ethical boundaries, minimizing unforeseen damage and managing expectations.

ANon-invasive testing

Non-invasive testing is a type of testing that aims to minimize damage, but it doesn't inherently provide legal protection against liability for any damage that might still occur.

BManual testing

Manual testing is a method of assessment and does not, by itself, provide liability protection.

CVulnerability scans

Vulnerability scans are a tool or technique used in assessments and do not offer legal liability protection.

DRules of engagementCorrect

Rules of engagement (ROE) are crucial in an assessment plan as they formally define the scope, boundaries, authorized activities, and expected behaviors of the assessment team, including disclaimers and liability limitations. This document protects the assessment team by outlining what is permitted and the agreed-upon responsibilities.

Concept tested: Rules of Engagement purpose

Source: https://csrc.nist.gov/publications/detail/sp/800-115/final

Topics

#Security Control Assessment#Assessment Plan#Rules of Engagement#Liability

Community Discussion

No community discussion yet for this question.

Full CGRC Practice