nerdexam
Isaca

CISM · Question #442

Which of the following is MOST important to have in place when conducting a security control assessment of a system?

The correct answer is D. Assurance test plan. An assurance test plan is most important when conducting a security control assessment, as it provides a structured approach to evaluate the effectiveness of controls. It defines testing methods, expected outcomes, and criteria for success, ensuring that assessments are consisten

Submitted by ricky.ec· Apr 18, 2026Information Security Program Development and Management

Question

Which of the following is MOST important to have in place when conducting a security control assessment of a system?

Options

  • ASecurity documentation
  • BControl specifications
  • CScanning tools
  • DAssurance test plan

How the community answered

(32 responses)
  • B
    3% (1)
  • C
    6% (2)
  • D
    91% (29)

Explanation

An assurance test plan is most important when conducting a security control assessment, as it provides a structured approach to evaluate the effectiveness of controls. It defines testing methods, expected outcomes, and criteria for success, ensuring that assessments are consistent and reliable. While security documentation, control specifications, and scanning tools support the process, they do not directly ensure a comprehensive and systematic evaluation like an assurance test plan does.

Topics

#Security control assessment#Assurance test plan#Control testing#Security program management

Community Discussion

No community discussion yet for this question.

Full CISM Practice