Study. uk . com
  1. Home
  2. All questions
  3. Question 334

CISM study material · question 334 of 1000

A system-level assessment must decide whether to include weaknesses in the controls the system inherits. What does SP 800-30 say about this choice?

  1. Inherited controls must always be included, without exception, because a weakness in a common control reaches every system that inherits it
  2. Inherited controls are assessed only by the common control provider itself, and the inheriting system simply records the provider's own result unexamined below
  3. The scope may place the system in its architectural context so inherited vulnerabilities count, or limit it to the system alone
  4. Inherited controls must always be excluded from a system-level assessment, since they sit outside that system's own authorisation boundary
Show the answer

Answer: C. The scope may place the system in its architectural context so inherited vulnerabilities count, or limit it to the system alone

SP 800-30 states the scope of a system-level assessment can place the system in its architectural context so vulnerabilities in inherited controls are taken into consideration, or can be limited solely to the system itself.

Source: NIST SP 800-30 Rev. 1 (NIST) — Task 1-2 Identify Scope

Challenge yourself on this topic → Study as cards