Study. uk . com
  1. Home
  2. All questions
  3. Question 59

CISSP study material · question 59 of 500

An energy utility is standing up an information security continuous monitoring programme and already maintains a current inventory of the systems it owns. To deliver the remaining aims of such a programme, which two capabilities must it add? Choose two.

  1. Evidence showing whether the deployed security controls are actually effective
  2. Awareness of the threats and vulnerabilities that bear on the systems in that inventory
  3. A quarterly penetration test that certifies residual risk as acceptable to the sponsor
  4. An annual authorisation package that stands in for control assessment between authorisations
Show the answer

Answer: B. Awareness of the threats and vulnerabilities that bear on the systems in that inventory
A. Evidence showing whether the deployed security controls are actually effective

Continuous monitoring delivers asset awareness, threat and vulnerability awareness, and control-effectiveness evidence together. Periodic authorisation packages and scheduled tests supply no ongoing effectiveness picture.

Source: NIST SP 800-137 (NIST) — SP 800-137 > Abstract

Challenge yourself on this topic → Study as cards