nerdexam
(ISC)2

CGRC · Question #695

An updated risk assessment in response to the security control assessment along with inputs from the risk executive helps to determine and prioritize... Response:

The correct answer is B. Initial remediation actions. An updated risk assessment, informed by security control assessments and risk executive input, directly supports the determination and prioritization of initial remediation actions needed to address identified vulnerabilities. This process aims to mitigate risks effectively and…

Security and Privacy Governance, Risk Management, and Compliance Program

Question

An updated risk assessment in response to the security control assessment along with inputs from the risk executive helps to determine and prioritize... Response:

Options

  • APlan of action and milestones
  • BInitial remediation actions
  • CFailed controls
  • DControl reassessments

How the community answered

(27 responses)
  • A
    4% (1)
  • B
    93% (25)
  • C
    4% (1)

Why each option

An updated risk assessment, informed by security control assessments and risk executive input, directly supports the determination and prioritization of initial remediation actions needed to address identified vulnerabilities. This process aims to mitigate risks effectively and efficiently.

APlan of action and milestones

A Plan of Action and Milestones (POA&M) is a document that lists remediation actions and timelines, but the immediate output of the assessment and risk executive input is the determination and prioritization of those actions themselves.

BInitial remediation actionsCorrect

When a security control assessment reveals deficiencies, and an updated risk assessment is performed with input from the risk executive, the primary goal is to determine and prioritize the necessary initial remediation actions. These actions are immediate steps taken to address the most critical vulnerabilities and weaknesses identified, before formulating a long-term Plan of Action and Milestones (POA&M) for ongoing improvement.

CFailed controls

Failed controls are an input to the assessment, not what is prioritized as an output.

DControl reassessments

Control reassessments are done after remediation, not determined and prioritized as an initial outcome.

Concept tested: Risk management framework - remediation

Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-37r2.pdf

Topics

#Risk Assessment#Remediation Prioritization#Control Assessment Response#Risk Executive Input

Community Discussion

No community discussion yet for this question.

Full CGRC Practice