Study. uk . com
  1. Home
  2. All questions
  3. Question 393

CISM study material · question 393 of 1000

Which four things does continuous assessment do after a system's initial authorisation?

  1. Frames, assesses, responds to and monitors risk
  2. Tracks changes, analyses their security impact, adjusts controls and the security plan, and reports status to officials
  3. Identifies, assesses, prioritises and monitors the weaknesses that are recorded in the system's own plan of action and milestones
  4. Detects, contains, eradicates and then recovers from each of the incidents that arise once the system has entered live operational use
Show the answer

Answer: B. Tracks changes, analyses their security impact, adjusts controls and the security plan, and reports status to officials

NIST describes continuous assessment as monitoring the initial accreditation to track changes to the system, analyse the security impact of those changes, adjust the controls and security plan, and report security status to appropriate officials.

Source: NIST SP 800-100 (NIST) — Table 2-1 Continuous Assessment

Challenge yourself on this topic → Study as cards