CGRC · Question #87
What is the purpose of the assess step? Response:
The correct answer is B. To determine if the selected controls are implement correctly, functioning as required, and. The primary purpose of the assess step in a security framework is to determine whether selected security controls are implemented correctly, operating as intended, and producing the desired security outcome.
Question
What is the purpose of the assess step? Response:
Options
- ATo find and remediate system vulnerabilities
- BTo determine if the selected controls are implement correctly, functioning as required, and
- CTo identify and eliminate risk factors
- DTo logically test and evaluate information systems
How the community answered
(25 responses)- B88% (22)
- C4% (1)
- D8% (2)
Why each option
The primary purpose of the assess step in a security framework is to determine whether selected security controls are implemented correctly, operating as intended, and producing the desired security outcome.
While vulnerabilities might be found during assessment, the "remediate" part is typically addressed in the Monitor step (Step 6) or as part of the overall risk management process, not solely the purpose of the assess step.
In the NIST Risk Management Framework (RMF), the Assess step (Step 4) involves conducting security control assessments to determine the effectiveness of security controls in an information system. This means evaluating if the controls are correctly implemented, operating as intended, and achieving the specified security requirements.
Identifying risk factors is part of the Categorize and Select steps, and eliminating them is an ongoing process, not the sole purpose of the assess step.
To logically test and evaluate information systems is too vague; the assess step specifically focuses on security controls and their effectiveness against requirements.
Concept tested: NIST RMF - Assess step purpose
Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-37r2.pdf
Topics
Community Discussion
No community discussion yet for this question.