CGRC · Question #88
Which of the following BEST defines the purpose of security assessment? Response:
The correct answer is B. To determine the extent to which the security controls are implemented correctly and operating as. The best definition of security assessment is determining the extent to which security controls are correctly implemented, operating as intended, and producing the desired security outcomes.
Question
Which of the following BEST defines the purpose of security assessment? Response:
Options
- ATo determine if the remaining known vulnerability pose an acceptable level of risk
- BTo determine the extent to which the security controls are implemented correctly and operating as
- CTo perform oversight and monitor the security controls in the information system (IS)
- DTo perform initial risk estimate and security categorization of the information system (IS)
How the community answered
(45 responses)- A2% (1)
- B89% (40)
- C2% (1)
- D7% (3)
Why each option
The best definition of security assessment is determining the extent to which security controls are correctly implemented, operating as intended, and producing the desired security outcomes.
While assessments inform risk decisions, determining an "acceptable level of risk" is the responsibility of the Authorizing Official during the Authorize step, not the primary purpose of the assessment itself.
Security assessment, particularly within frameworks like NIST RMF, is a systematic process of evaluating the effectiveness of security controls. This evaluation focuses on whether the controls are implemented accurately, functioning reliably as designed, and achieving the intended security objectives to protect the information system and its data.
Performing oversight and monitoring is the purpose of the Monitor step (Step 6), which follows assessment, not the assessment itself.
Performing initial risk estimation and security categorization is part of the Categorize step (Step 1), which occurs at the very beginning of the RMF process, not during assessment.
Concept tested: Security assessment purpose and scope
Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-37r2.pdf
Topics
Community Discussion
No community discussion yet for this question.