- Home
- All questions
- Question 109
CISSP study material · question 109 of 500
A system was assessed as adequately controlled at authorisation four years ago and has not been reassessed since, on the grounds that nothing about it has changed. What does NIST SP 800-30 say about that reasoning?
Show the answer
Answer: C. Controls degrade as missions, environments, technologies and threats change, so assessment continues across the life cycle.
Existing controls can become inadequate as the surrounding conditions evolve, which is why risk assessment runs through the whole life cycle and continuous monitoring maintains awareness.
Source: NIST SP 800-30 Rev. 1 (NIST) — SP 800-30 Rev. 1 > 2.3.1 Vulnerabilities and Predisposing Conditions