Study. uk . com
  1. Home
  2. All questions
  3. Question 186

CISM study material · question 186 of 1000

Controls assessed as effective at deployment are found to be much less effective five years later, without any change being made to them. What does SP 800-30 conclude from this tendency?

  1. Control degradation is a documentation problem rather than a risk one, and is corrected by reissuing the control description
  2. Risk assessment must continue through the whole life cycle, supported by continuous monitoring
  3. Controls should be replaced on a fixed five-year cycle
  4. Effectiveness assessments should be performed only at deployment
Show the answer

Answer: B. Risk assessment must continue through the whole life cycle, supported by continuous monitoring

SP 800-30 draws two conclusions from control decay: assessment has to continue across the whole life cycle, and continuous monitoring is what keeps it current.

Source: NIST SP 800-30 Rev. 1 (NIST) — Sec. 2.3.1 Risk Models — Vulnerabilities

Challenge yourself on this topic → Study as cards