CGRC Exam Question 26
Which plan documents objectives for the security control assessment & details how to conduct such an assessment and records assessment procedures (Security Plan, Assessment Plan, POAM)? Response:
CGRC Exam Question 27
In which of the following testing methodologies do assessors use all available documentation and work under no constraints, and attempt to circumvent the security features of an information system? Response:
CGRC Exam Question 28
You are the project manager for the NHH project.
You are working with your project team to examine the project from four different defined perspectives to increase the breadth of identified risks by including internally generated risks.
What risk identification approach are you using in this example?
You are working with your project team to examine the project from four different defined perspectives to increase the breadth of identified risks by including internally generated risks.
What risk identification approach are you using in this example?
CGRC Exam Question 29
Which of the following statements about the availability concept of Information security management is true?
Response:
Response:
CGRC Exam Question 30
The RMF Step and task where a Continuous Monitoring strategy that monitors the effectiveness of the selected security controls is created.
Response:
Response:
