Study. uk . com
  1. Home
  2. All questions
  3. Question 109

CISSP study material · question 109 of 500

A system was assessed as adequately controlled at authorisation four years ago and has not been reassessed since, on the grounds that nothing about it has changed. What does NIST SP 800-30 say about that reasoning?

  1. A four-year interval is acceptable for systems categorised below high impact.
  2. Continuous monitoring replaces the need for any further risk assessment.
  3. Controls degrade as missions, environments, technologies and threats change, so assessment continues across the life cycle.
  4. Reassessment is required only after a change to the system's categorisation.
Show the answer

Answer: C. Controls degrade as missions, environments, technologies and threats change, so assessment continues across the life cycle.

Existing controls can become inadequate as the surrounding conditions evolve, which is why risk assessment runs through the whole life cycle and continuous monitoring maintains awareness.

Source: NIST SP 800-30 Rev. 1 (NIST) — SP 800-30 Rev. 1 > 2.3.1 Vulnerabilities and Predisposing Conditions

Challenge yourself on this topic → Study as cards