nerdexam
(ISC)2

CGRC · Question #87

What is the purpose of the assess step? Response:

The correct answer is B. To determine if the selected controls are implement correctly, functioning as required, and. The primary purpose of the assess step in a security framework is to determine whether selected security controls are implemented correctly, operating as intended, and producing the desired security outcome.

Assessment/Audit of Security and Privacy Controls

Question

What is the purpose of the assess step? Response:

Options

  • ATo find and remediate system vulnerabilities
  • BTo determine if the selected controls are implement correctly, functioning as required, and
  • CTo identify and eliminate risk factors
  • DTo logically test and evaluate information systems

How the community answered

(25 responses)
  • B
    88% (22)
  • C
    4% (1)
  • D
    8% (2)

Why each option

The primary purpose of the assess step in a security framework is to determine whether selected security controls are implemented correctly, operating as intended, and producing the desired security outcome.

ATo find and remediate system vulnerabilities

While vulnerabilities might be found during assessment, the "remediate" part is typically addressed in the Monitor step (Step 6) or as part of the overall risk management process, not solely the purpose of the assess step.

BTo determine if the selected controls are implement correctly, functioning as required, andCorrect

In the NIST Risk Management Framework (RMF), the Assess step (Step 4) involves conducting security control assessments to determine the effectiveness of security controls in an information system. This means evaluating if the controls are correctly implemented, operating as intended, and achieving the specified security requirements.

CTo identify and eliminate risk factors

Identifying risk factors is part of the Categorize and Select steps, and eliminating them is an ongoing process, not the sole purpose of the assess step.

DTo logically test and evaluate information systems

To logically test and evaluate information systems is too vague; the assess step specifically focuses on security controls and their effectiveness against requirements.

Concept tested: NIST RMF - Assess step purpose

Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-37r2.pdf

Topics

#Control Assessment#Security Controls#Privacy Controls#Assessment Process

Community Discussion

No community discussion yet for this question.

Full CGRC Practice