nerdexam
(ISC)2

CGRC · Question #705

Which of the following are the objectives of the security certification documentation task? Each correct answer represents a complete solution. Choose all that apply. Response:

The correct answer is A. To prepare the Plan of Action and Milestones (POAM) based on the security assessment B. To provide the certification findings and recommendations to the information system owner C. To assemble the final security accreditation package and then submit it to the authorizing o fficial D. To update the system security plan based on the results of the security assessment. The security certification documentation task involves a comprehensive set of objectives including preparing remediation plans, reporting findings, compiling accreditation packages, and updating system security plans.

Assessment/Audit of Security and Privacy Controls

Question

Which of the following are the objectives of the security certification documentation task? Each correct answer represents a complete solution. Choose all that apply. Response:

Options

  • ATo prepare the Plan of Action and Milestones (POAM) based on the security assessment
  • BTo provide the certification findings and recommendations to the information system owner
  • CTo assemble the final security accreditation package and then submit it to the authorizing o fficial
  • DTo update the system security plan based on the results of the security assessment

How the community answered

(52 responses)
  • A
    100% (52)

Why each option

The security certification documentation task involves a comprehensive set of objectives including preparing remediation plans, reporting findings, compiling accreditation packages, and updating system security plans.

ATo prepare the Plan of Action and Milestones (POAM) based on the security assessmentCorrect

Based on the security assessment, a Plan of Action and Milestones (POAM) is prepared to track and manage the remediation of identified vulnerabilities and weaknesses.

BTo provide the certification findings and recommendations to the information system ownerCorrect

Providing certification findings and recommendations to the information system owner is crucial for transparency and informed decision-making regarding the system's security posture.

CTo assemble the final security accreditation package and then submit it to the authorizing o fficialCorrect

Assembling the final security accreditation package for submission to the authorizing official is a key objective to enable an informed authorization decision.

DTo update the system security plan based on the results of the security assessmentCorrect

Updating the system security plan is essential to reflect the current security state, implemented controls, and any changes or remediation actions resulting from the security assessment.

Concept tested: Objectives of security certification documentation

Source: https://csrc.nist.gov/publications/detail/sp/800-37/rev2/final

Topics

#Security Certification#RMF Documentation#POAM#Accreditation Package

Community Discussion

No community discussion yet for this question.

Full CGRC Practice