nerdexam
(ISC)2

CISSP · Question #1495

With what frequency should monitoring of a control occur when implementing Information Security Continuous Monitoring (ISCM) solutions?

The correct answer is C. At a rate concurrent with the volatility of the security control. Monitoring of a control should occur at a rate concurrent with the volatility of the security control when implementing Information Security Continuous Monitoring (ISCM) solutions. ISCM is a process that involves maintaining the ongoing awareness of the security status, events, a

Submitted by ahmad_uae· Mar 5, 2026Security Operations

Question

With what frequency should monitoring of a control occur when implementing Information Security Continuous Monitoring (ISCM) solutions?

Options

  • AContinuously without exception for all security controls
  • BBefore and after each change of the control
  • CAt a rate concurrent with the volatility of the security control
  • DOnly during system implementation and decommissioning

How the community answered

(46 responses)
  • A
    2% (1)
  • B
    13% (6)
  • C
    78% (36)
  • D
    7% (3)

Explanation

Monitoring of a control should occur at a rate concurrent with the volatility of the security control when implementing Information Security Continuous Monitoring (ISCM) solutions. ISCM is a process that involves maintaining the ongoing awareness of the security status, events, and activities of a system or network, by collecting, analyzing, and reporting the security data and information, using various methods and tools. ISCM can provide several benefits, such as: Improving the security and risk management of the system or network by identifying and addressing the security weaknesses and gaps Enhancing the security and decision making of the system or network by providing the evidence and information for the security analysis, evaluation, and reporting Increasing the security and improvement of the system or network by providing the feedback and input for the security response, remediation, and optimization Facilitating the compliance and alignment of the system or network with the internal or external requirements and standards A security control is a measure or mechanism that is implemented to protect the system or network from the security threats or risks, by preventing, detecting, or correcting the security incidents or impacts. A security control can have various types, such as administrative, technical, or physical, and various attributes, such as preventive, detective, or corrective. A security control can also have different levels of volatility, which is the degree or frequency of change or variation of the security control, due to various factors, such as the security requirements, the threat landscape, or the system or network environment. Monitoring of a control should occur at a rate concurrent with the volatility of the security control when implementing ISCM solutions, because it can ensure that the ISCM solutions can capture and reflect the current and accurate state and performance of the security control, and can identify and report any issues or risks that might affect the security control. Monitoring of a control at a rate concurrent with the volatility of the security control can also help to optimize the ISCM resources and efforts, by allocating them according to the priority and urgency of the security

Topics

#Continuous monitoring#Security controls#Volatility#Monitoring frequency

Community Discussion

No community discussion yet for this question.

Full CISSP Practice