CGRC · Question #91
Why is the early selection of assessors important to organizations implementing a systems security engineering approach? Response:
The correct answer is B. Early selection of assessors support verification and validation activities that occur throughout the. The early involvement of security assessors is crucial in a systems security engineering approach because they provide continuous verification and validation throughout the entire system lifecycle.
Question
Why is the early selection of assessors important to organizations implementing a systems security engineering approach? Response:
Options
- AEarly selection of assessors assess all implement security controls
- BEarly selection of assessors support verification and validation activities that occur throughout the
- CEarly selection of assessors voilates security requirements
- DEarly selection of assessors complete security control assessments in a timely manner
How the community answered
(40 responses)- B95% (38)
- C3% (1)
- D3% (1)
Why each option
The early involvement of security assessors is crucial in a systems security engineering approach because they provide continuous verification and validation throughout the entire system lifecycle.
Assessors do not necessarily assess all implemented security controls, but rather a subset or specific controls as part of the overall assessment strategy.
Early selection of assessors is crucial because they provide continuous support for verification and validation activities from the initial stages through the entire system development lifecycle. This integration helps identify and address security issues proactively, ensuring the system meets its security objectives effectively.
Early selection of assessors enhances security by integrating expertise, not violating security requirements.
While timely completion of assessments is a goal, the primary importance of early selection is the continuous support for verification and validation, which contributes to timely completion but is not the sole reason.
Concept tested: Systems security engineering assessment role
Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-160v1r1.pdf
Topics
Community Discussion
No community discussion yet for this question.