CGRC · Question #7
What is the MOST appropriate action to take after weaknesses or deficiencies in controls are corrected? Response:
The correct answer is B. The remediated controls are reassessed. After weaknesses in controls are corrected, the most appropriate next step is to reassess the remediated controls to ensure the corrections were effective.
Question
What is the MOST appropriate action to take after weaknesses or deficiencies in controls are corrected? Response:
Options
- AThe system is given an Authority to Operate (ATO)
- BThe remediated controls are reassessed
- CThe assessment report is generated
- DThe original assessment results are changed
How the community answered
(32 responses)- A6% (2)
- B88% (28)
- C3% (1)
- D3% (1)
Why each option
After weaknesses in controls are corrected, the most appropriate next step is to reassess the remediated controls to ensure the corrections were effective.
Granting an Authority to Operate (ATO) is a final decision made after all assessments, including reassessments of remediated controls, have been completed and found satisfactory.
Once weaknesses or deficiencies in controls are corrected (remediated), it is crucial to reassess those remediated controls to verify that the implemented corrections are effective and have successfully addressed the identified issues. This step confirms the security posture improvement before proceeding with authorization.
An assessment report is generated before or immediately after the initial assessment of controls, documenting initial findings, and is typically updated or supplemented after remediation and reassessment.
The original assessment results describe the initial state; they should not be changed, but rather new results from the reassessment should be documented to show the improvement.
Concept tested: Risk management - remediation and reassessment
Source: https://csrc.nist.gov/publications/detail/sp/800-37/rev-2/final
Topics
Community Discussion
No community discussion yet for this question.