Question 1 of 10 · Security and Privacy Governance, Risk Management, and Compliance Program
Which separation does the framework require absolutely?
The framework insists that whoever implements a control is not the person who assesses it, so the assessment is independent. The other role pairs can be separated or combined depending on the organisation.
Question 2 of 10 · Scope of the System
What is the effect of categorisation on the rest of the lifecycle?
Categorisation sets the impact level, which selects the control baseline, and every later step (implementation, assessment, authorisation, monitoring) builds on that baseline. Assessment methods and periods follow from it.
Question 3 of 10 · Selection and Approval of Framework, Security, and Privacy Controls
Which describes an overlay?
An overlay is a set of supplementary controls and guidance for a particular community, technology or purpose, applied on top of a baseline. It is not a framework mapping or a system's own tailoring record.
Question 4 of 10 · Implementation of Security and Privacy Controls
Why must the plan describe implementation rather than restate the control?
Restating a control only shows it was selected; the plan must say how this system implements it so the assessor can test that implementation. Formatting rules and the official's reading are secondary.
Question 5 of 10 · Assessment/Audit of Security and Privacy Controls
What does the examine method involve?
Examine means reviewing documents, records, mechanisms or activities. Questioning people is interview, and exercising the control is test.
Question 6 of 10 · System Compliance
Which is the most common failure at the authorisation stage?
The most common failure is a package that describes the intended state rather than how the system actually operates, so the official authorises something that does not exist. Lateness and detail are lesser problems.
Question 7 of 10 · Compliance Maintenance
Which describes a significant change?
A significant change is one likely to affect the system's security state or risk position, which is what triggers reassessment. The number of control families touched or whether a change request is raised does not decide it.
Question 8 of 10 · Security and Privacy Governance, Risk Management, and Compliance Program
Which describes the programme's treatment of legacy systems?
Legacy systems are assessed like any other, with their exposure documented, owned and time-bound. Exempting them or lowering the baseline hides exactly the risk they carry.
Question 9 of 10 · Scope of the System
What is the consequence of a boundary that no longer matches the system?
If the boundary no longer matches the system, the assessment covered something different from what is running, so its conclusions may not apply. Updating documents later does not fix decisions already made on the wrong scope.
Question 10 of 10 · Selection and Approval of Framework, Security, and Privacy Controls
Where are selected controls and their implementation recorded?
Selected controls and how they are implemented are recorded in the system security plan. Risk assessment, monitoring strategy and assessment reports are separate artefacts that refer to it.
0 of 10
Security and Privacy Governance, Risk Management, and Compliance Program
Scope of the System
Selection and Approval of Framework, Security, and Privacy Controls
Implementation of Security and Privacy Controls
Assessment/Audit of Security and Privacy Controls
System Compliance
Compliance Maintenance
Which domains cost you the points? Members see a breakdown by domain and a study plan built from it.