CGRC · Question #704
There are different types of control assessments depending on the assessment objectives. Which of the following is not a type of control assessments? Response:
The correct answer is B. Risk assessment. Control assessments evaluate the effectiveness and implementation of security controls, while risk assessment is a distinct, preliminary process that identifies and analyzes risks.
Question
There are different types of control assessments depending on the assessment objectives. Which of the following is not a type of control assessments? Response:
Options
- ADevelopmental testing and evaluation
- BRisk assessment
- CIndipendent verification and validation
- DAudits
How the community answered
(21 responses)- B95% (20)
- C5% (1)
Why each option
Control assessments evaluate the effectiveness and implementation of security controls, while risk assessment is a distinct, preliminary process that identifies and analyzes risks.
Developmental testing and evaluation involves testing controls during their development life cycle to ensure they meet requirements, making it a type of control assessment.
Risk assessment is a process of identifying, analyzing, and evaluating risks to an organization's information systems and data. It is a foundational step that informs the selection and implementation of security controls, but it is not itself a method for assessing the controls already in place.
Independent verification and validation (IV&V) involves evaluation by a third party to verify software and system controls, which is a method of control assessment.
Audits are formal examinations of an organization's systems and controls to determine compliance and effectiveness, often including control assessments.
Concept tested: Types of security control assessments
Source: https://csrc.nist.gov/publications/detail/sp/800-53a/rev5/final
Topics
Community Discussion
No community discussion yet for this question.