ISC2 Governance, Risk and Compliance (CGRC) Practice Question
After a cloud-based information system finishes implementation and enters the testing phase of the SDLC, the project manager wants to align security work with NIST guidance before requesting an authorization to operate. Which action best fits the objectives of the testing phase?
Conduct an independent assessment to verify that the implemented security and privacy controls are operating as intended.
Begin continuous monitoring by deploying automated dashboards to track security metrics in production.
Create and approve the final data disposal and media sanitization plan for end-of-life activities.
Define detailed security requirements and tailor the baseline control set for the system.
During the SDLC testing phase, security professionals verify that the safeguards integrated earlier actually work. NIST SP 800-64 and the RMF (NIST SP 800-37) state that this is the point at which an independent assessor evaluates the implemented security and privacy controls to confirm they are correctly implemented, operating as intended, and producing the desired outcome. Selecting controls, planning for media disposal, or launching a full continuous-monitoring program occur in other SDLC or RMF steps (planning, disposition, or ongoing authorization). Therefore, performing an independent security control assessment is the most appropriate activity for this phase.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is NIST SP 800-64 and its importance in SDLC?
Open an interactive chat with Bash
What is an independent assessment in the context of security controls?
Open an interactive chat with Bash
Why is continuous monitoring not initiated during the SDLC testing phase?
Open an interactive chat with Bash
ISC2 Governance, Risk and Compliance (CGRC)
Security and Privacy Governance, Risk Management, and Compliance Program
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .