nerdexam
(ISC)2

CGRC · Question #691

Prior to completion of the security assessment report (SAR), what type of analysis is performed when agile, iterative development is used? Response:

The correct answer is C. Incremental assessment. When employing agile and iterative development methodologies, an incremental assessment is performed prior to the completion of the Security Assessment Report (SAR) to continuously evaluate security posture as the system evolves.

Assessment/Audit of Security and Privacy Controls

Question

Prior to completion of the security assessment report (SAR), what type of analysis is performed when agile, iterative development is used? Response:

Options

  • ARegression analysis
  • BInterim assessment
  • CIncremental assessment
  • DExecutive assessment

How the community answered

(26 responses)
  • A
    4% (1)
  • B
    8% (2)
  • C
    77% (20)
  • D
    12% (3)

Why each option

When employing agile and iterative development methodologies, an incremental assessment is performed prior to the completion of the Security Assessment Report (SAR) to continuously evaluate security posture as the system evolves.

ARegression analysis

Regression analysis is a statistical process for estimating the relationships among variables and is not a specific type of security assessment used in agile development.

BInterim assessment

An interim assessment might occur, but 'incremental assessment' specifically describes the continuous nature of assessments within an iterative development model.

CIncremental assessmentCorrect

When agile, iterative development methodologies are used, security assessments are often conducted incrementally throughout the development lifecycle rather than as a single, large assessment at the end. This 'incremental assessment' approach allows for continuous feedback on the security posture of the evolving system, enabling early identification and remediation of vulnerabilities before the final Security Assessment Report (SAR) is produced.

DExecutive assessment

An executive assessment is usually a high-level review for leadership and not the technical analysis performed during iterative development.

Concept tested: Agile Security Assessment in RMF

Source: https://csrc.nist.gov/publications/detail/sp/800-37/rev2/final

Topics

#Agile security#Incremental assessment#Security Assessment Report (SAR)#RMF Assessment

Community Discussion

No community discussion yet for this question.

Full CGRC Practice