nerdexam
(ISC)2

CGRC · Question #80

During the security impact analysis vulnerabilities were uncovered in the information system. Which of the following documents should address the outstanding items? Response:

The correct answer is A. Plan of action and milestones. When vulnerabilities are found during a security impact analysis, a Plan of Action and Milestones (POA&M) is the appropriate document to track and manage the remediation efforts. It outlines the specific steps, resources, and timelines for addressing identified weaknesses.

Assessment/Audit of Security and Privacy Controls

Question

During the security impact analysis vulnerabilities were uncovered in the information system. Which of the following documents should address the outstanding items? Response:

Options

  • APlan of action and milestones
  • BSystem security plan
  • CSystem discrepancy plan
  • DSystem deficiency plan

How the community answered

(24 responses)
  • A
    88% (21)
  • C
    8% (2)
  • D
    4% (1)

Why each option

When vulnerabilities are found during a security impact analysis, a Plan of Action and Milestones (POA&M) is the appropriate document to track and manage the remediation efforts. It outlines the specific steps, resources, and timelines for addressing identified weaknesses.

APlan of action and milestonesCorrect

A Plan of Action and Milestones (POA&M) is the official document used to track and manage the remediation of identified security weaknesses and vulnerabilities. It details the specific actions to be taken, resources required, and target completion dates to address outstanding items from security assessments or impact analyses.

BSystem security plan

The System Security Plan (SSP) describes the system's security posture and controls, not a plan for remediation of vulnerabilities found.

CSystem discrepancy plan

"System discrepancy plan" is not a recognized official document for addressing vulnerabilities in the RMF context.

DSystem deficiency plan

"System deficiency plan" is not a recognized official document for addressing vulnerabilities in the RMF context.

Concept tested: RMF - Plan of Action and Milestones (POA&M)

Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-37r2.pdf

Topics

#Plan of Action and Milestones (POAM)#Vulnerability Management#Risk Management Framework (RMF) Documentation#Security Assessment Outcomes

Community Discussion

No community discussion yet for this question.

Full CGRC Practice