CGRC · Question #695
An updated risk assessment in response to the security control assessment along with inputs from the risk executive helps to determine and prioritize... Response:
The correct answer is B. Initial remediation actions. An updated risk assessment, informed by security control assessments and risk executive input, directly supports the determination and prioritization of initial remediation actions needed to address identified vulnerabilities. This process aims to mitigate risks effectively and…
Question
An updated risk assessment in response to the security control assessment along with inputs from the risk executive helps to determine and prioritize... Response:
Options
- APlan of action and milestones
- BInitial remediation actions
- CFailed controls
- DControl reassessments
How the community answered
(27 responses)- A4% (1)
- B93% (25)
- C4% (1)
Why each option
An updated risk assessment, informed by security control assessments and risk executive input, directly supports the determination and prioritization of initial remediation actions needed to address identified vulnerabilities. This process aims to mitigate risks effectively and efficiently.
A Plan of Action and Milestones (POA&M) is a document that lists remediation actions and timelines, but the immediate output of the assessment and risk executive input is the determination and prioritization of those actions themselves.
When a security control assessment reveals deficiencies, and an updated risk assessment is performed with input from the risk executive, the primary goal is to determine and prioritize the necessary initial remediation actions. These actions are immediate steps taken to address the most critical vulnerabilities and weaknesses identified, before formulating a long-term Plan of Action and Milestones (POA&M) for ongoing improvement.
Failed controls are an input to the assessment, not what is prioritized as an output.
Control reassessments are done after remediation, not determined and prioritized as an initial outcome.
Concept tested: Risk management framework - remediation
Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-37r2.pdf
Topics
Community Discussion
No community discussion yet for this question.