CSSLP · Question #81
Della works as a security engineer for BlueWell Inc. She wants to establish configuration management and control procedures that will document proposed or actual changes to the information system…
The correct answer is C. Continuous Monitoring. Establishing configuration management and control procedures to document changes to an information system is a key activity within the Continuous Monitoring phase of the NIST SP 800-37 Risk Management Framework (RMF).
Question
Della works as a security engineer for BlueWell Inc. She wants to establish configuration management and control procedures that will document proposed or actual changes to the information system. Which of the following phases of NIST SP 800-37 C&A methodology will define the above task?
Options
- AInitiation
- BSecurity Certification
- CContinuous Monitoring
- DSecurity Accreditation
How the community answered
(25 responses)- A8% (2)
- C88% (22)
- D4% (1)
Why each option
Establishing configuration management and control procedures to document changes to an information system is a key activity within the Continuous Monitoring phase of the NIST SP 800-37 Risk Management Framework (RMF).
The Initiation phase involves defining and categorizing the information system and selecting applicable security controls, not establishing ongoing change management procedures.
Security Certification involves assessing and evaluating the security controls of an information system to determine if they are implemented correctly and effectively.
Continuous Monitoring is the NIST SP 800-37 RMF phase where organizations maintain an ongoing awareness of their security and privacy posture by continuously assessing security controls, documenting changes, and responding to incidents. Configuration management and control procedures are essential elements of this phase, ensuring that all proposed or actual changes to the system are tracked and assessed for security impact to maintain the system's authorization status.
Security Accreditation is the formal declaration by a designated approving authority that an information system is authorized to operate, based on the security assessment and risk determination, rather than defining ongoing change control processes.
Concept tested: NIST RMF Continuous Monitoring phase
Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-37r2.pdf
Topics
Community Discussion
No community discussion yet for this question.