nerdexam
(ISC)2

CSSLP · Question #81

Della works as a security engineer for BlueWell Inc. She wants to establish configuration management and control procedures that will document proposed or actual changes to the information system…

The correct answer is C. Continuous Monitoring. Establishing configuration management and control procedures to document changes to an information system is a key activity within the Continuous Monitoring phase of the NIST SP 800-37 Risk Management Framework (RMF).

Secure Software Deployment, Operations, Maintenance

Question

Della works as a security engineer for BlueWell Inc. She wants to establish configuration management and control procedures that will document proposed or actual changes to the information system. Which of the following phases of NIST SP 800-37 C&A methodology will define the above task?

Options

  • AInitiation
  • BSecurity Certification
  • CContinuous Monitoring
  • DSecurity Accreditation

How the community answered

(25 responses)
  • A
    8% (2)
  • C
    88% (22)
  • D
    4% (1)

Why each option

Establishing configuration management and control procedures to document changes to an information system is a key activity within the Continuous Monitoring phase of the NIST SP 800-37 Risk Management Framework (RMF).

AInitiation

The Initiation phase involves defining and categorizing the information system and selecting applicable security controls, not establishing ongoing change management procedures.

BSecurity Certification

Security Certification involves assessing and evaluating the security controls of an information system to determine if they are implemented correctly and effectively.

CContinuous MonitoringCorrect

Continuous Monitoring is the NIST SP 800-37 RMF phase where organizations maintain an ongoing awareness of their security and privacy posture by continuously assessing security controls, documenting changes, and responding to incidents. Configuration management and control procedures are essential elements of this phase, ensuring that all proposed or actual changes to the system are tracked and assessed for security impact to maintain the system's authorization status.

DSecurity Accreditation

Security Accreditation is the formal declaration by a designated approving authority that an information system is authorized to operate, based on the security assessment and risk determination, rather than defining ongoing change control processes.

Concept tested: NIST RMF Continuous Monitoring phase

Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-37r2.pdf

Topics

#NIST SP 800-37#Continuous Monitoring#Configuration Management#Risk Management Framework

Community Discussion

No community discussion yet for this question.

Full CSSLP Practice