nerdexam
(ISC)2

CGRC · Question #651

What should the system owner use to prioritize mitigation actions when developing the plan of action and milestones (POA&M)? Response:

The correct answer is B. Risk assessment results. When developing a Plan of Action and Milestones (POA&M), the system owner should primarily use the results of risk assessments to prioritize mitigation actions. Risk assessment outcomes provide an objective basis for understanding the likelihood and impact of identified risks, gu

Security and Privacy Governance, Risk Management, and Compliance Program

Question

What should the system owner use to prioritize mitigation actions when developing the plan of action and milestones (POA&M)? Response:

Options

  • ABudget constraints
  • BRisk assessment results
  • CContinuous monitoring strategy
  • DRecommendations of the information owners

How the community answered

(39 responses)
  • A
    5% (2)
  • B
    90% (35)
  • C
    3% (1)
  • D
    3% (1)

Why each option

When developing a Plan of Action and Milestones (POA&M), the system owner should primarily use the results of risk assessments to prioritize mitigation actions. Risk assessment outcomes provide an objective basis for understanding the likelihood and impact of identified risks, guiding where resources should be focused.

ABudget constraints

Budget constraints are a practical consideration, but they are a limiting factor, not the primary input for prioritizing technical risks based on their severity.

BRisk assessment resultsCorrect

Risk assessment results provide the necessary data regarding the likelihood and impact of identified vulnerabilities and threats, which is critical for objectively prioritizing mitigation actions in a Plan of Action and Milestones (POA&M). High-risk items should receive higher priority.

CContinuous monitoring strategy

A continuous monitoring strategy is about ongoing oversight and detection, not the initial prioritization of actions in a POA&M.

DRecommendations of the information owners

While recommendations from information owners are valuable input, the comprehensive risk assessment results provide the holistic and objective basis for prioritization across all aspects of the system.

Concept tested: POA&M prioritization basis

Source: https://csrc.nist.gov/glossary/term/plan_of_action_and_milestones

Topics

#POA&M#Risk Prioritization#Mitigation Actions#Risk Assessment

Community Discussion

No community discussion yet for this question.

Full CGRC Practice