nerdexam
(ISC)2

CGRC · Question #7

What is the MOST appropriate action to take after weaknesses or deficiencies in controls are corrected? Response:

The correct answer is B. The remediated controls are reassessed. After weaknesses in controls are corrected, the most appropriate next step is to reassess the remediated controls to ensure the corrections were effective.

Assessment/Audit of Security and Privacy Controls

Question

What is the MOST appropriate action to take after weaknesses or deficiencies in controls are corrected? Response:

Options

  • AThe system is given an Authority to Operate (ATO)
  • BThe remediated controls are reassessed
  • CThe assessment report is generated
  • DThe original assessment results are changed

How the community answered

(32 responses)
  • A
    6% (2)
  • B
    88% (28)
  • C
    3% (1)
  • D
    3% (1)

Why each option

After weaknesses in controls are corrected, the most appropriate next step is to reassess the remediated controls to ensure the corrections were effective.

AThe system is given an Authority to Operate (ATO)

Granting an Authority to Operate (ATO) is a final decision made after all assessments, including reassessments of remediated controls, have been completed and found satisfactory.

BThe remediated controls are reassessedCorrect

Once weaknesses or deficiencies in controls are corrected (remediated), it is crucial to reassess those remediated controls to verify that the implemented corrections are effective and have successfully addressed the identified issues. This step confirms the security posture improvement before proceeding with authorization.

CThe assessment report is generated

An assessment report is generated before or immediately after the initial assessment of controls, documenting initial findings, and is typically updated or supplemented after remediation and reassessment.

DThe original assessment results are changed

The original assessment results describe the initial state; they should not be changed, but rather new results from the reassessment should be documented to show the improvement.

Concept tested: Risk management - remediation and reassessment

Source: https://csrc.nist.gov/publications/detail/sp/800-37/rev-2/final

Topics

#Control Remediation#Control Reassessment#Security Control Lifecycle

Community Discussion

No community discussion yet for this question.

Full CGRC Practice