CGRC · Question #696
Based on the results of the continuous monitoring process, all excluding one of the following key documents are updated. Response:
The correct answer is B. Continuous monitoring strategy. The continuous monitoring process typically updates the Plan of Action and Milestones, security and privacy assessment results, and the security plan to reflect ongoing system status and risks. However, the continuous monitoring strategy itself is the overarching document guiding
Question
Based on the results of the continuous monitoring process, all excluding one of the following key documents are updated. Response:
Options
- APlan of action and milestones
- BContinuous monitoring strategy
- CSecurity and privacy assessment results
- DSecurity plan
How the community answered
(27 responses)- B93% (25)
- C4% (1)
- D4% (1)
Why each option
The continuous monitoring process typically updates the Plan of Action and Milestones, security and privacy assessment results, and the security plan to reflect ongoing system status and risks. However, the continuous monitoring strategy itself is the overarching document guiding the process, not something typically updated by the results of that process.
The Plan of Action and Milestones (POA&M) is updated to reflect new vulnerabilities, risks, and completed remediation actions identified through continuous monitoring.
Continuous monitoring is designed to provide ongoing awareness of the security and privacy posture of information systems, leading to updates in documents like the Plan of Action and Milestones (POA&M) for remediation, the Security and Privacy Assessment Results with new findings, and the Security Plan to reflect current controls and operational status. The continuous monitoring strategy, however, defines how monitoring is performed, and while it might be periodically reviewed, it's not directly updated by the results of the monitoring process itself in the same way the other operational documents are.
Security and privacy assessment results are continuously updated to reflect the ongoing posture of the system, including any new vulnerabilities or control effectiveness changes.
The Security Plan is a living document that is updated to reflect changes in the system, its environment, and the implementation status of its security controls.
Concept tested: NIST RMF continuous monitoring
Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-137r1.pdf
Topics
Community Discussion
No community discussion yet for this question.