Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam CISSP All Questions

View all questions & answers for the CISSP exam

Exam CISSP topic 1 question 316 discussion

Actual exam question from ISC's CISSP
Question #: 316
Topic #: 1
[All CISSP Questions]

The initial security categorization should be done early in the system life cycle and should be reviewed periodically. Why is it important for this to be done correctly?

  • A. It determines the functional and operational requirements.
  • B. It determines the security requirements.
  • C. It affects other steps in the certification and accreditation process.
  • D. The system engineering process works with selected security controls.
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
CuteRabbit168
Highly Voted 2 years, 1 month ago
Selected Answer: B
B appears to be the better answer. Thoughts ?
upvoted 8 times
jackdryan
1 year, 6 months ago
B is correct
upvoted 1 times
...
...
rdy4u
Highly Voted 2 years ago
Selected Answer: B
The initial security categorization for the information and the information system should be done during the initiation phase of the system development life cycle along with an initial risk assessment. The initial risk assessment defines the threat environment in which the information system will operate and includes an initial description of the basic security needs of the system. https://csrc.nist.gov/csrc/media/projects/risk-management/documents/categorize/faq-categorize-step1.pdf
upvoted 7 times
...
YesPlease
Most Recent 11 months, 1 week ago
Selected Answer: B
Answer B) The initial security categorization for the information and the system is performed during the initiation phase of the system development life cycle along with an initial security risk assessment. The initial risk assessment defines the threat environment in which the system operates and includes an initial description of the basic security needs of the system. https://csrc.nist.gov/CSRC/media/Projects/risk-management/documents/02-Categorize%20Step/NIST%20RMF%20Categorize%20Step-FAQs.pdf A is wrong as it doesn't determine functional and operational requirements. C is wrong as no one was talking about getting any certification/accreditation for the application D is wrong as some system engineering processes may or may not be dependent on selected security controls.
upvoted 1 times
...
bherto39
1 year, 2 months ago
Selected Answer: C
C. It affects other steps in the certification and accreditation process. The correct categorization of a system's security level is crucial because it has a cascading effect on various aspects of the system's development, implementation, and management. When the initial security categorization is done correctly, it helps in determining the appropriate security requirements, selecting the necessary security controls, and defining the overall security posture of the system. Additionally, it impacts other steps in the certification and accreditation process, such as risk assessments, security control selection, and the development of security documentation. Incorrect categorization can lead to inadequate security measures or overburdening the system with unnecessary security controls, both of which can have serious consequences for the system's effectiveness and efficiency. Therefore, getting the initial security categorization right is a critical foundational step in the security lifecycle of a system.
upvoted 1 times
...
user009
1 year, 8 months ago
The correct answer is B. Explanation: The initial security categorization helps to determine the security requirements for the system. These requirements will guide the selection, implementation, and testing of security controls. If the initial security categorization is not done correctly, the system may not be adequately protected against threats and vulnerabilities. It is important to periodically review the security categorization to ensure that it remains appropriate as the system evolves over time.
upvoted 2 times
...
Dee83
1 year, 10 months ago
C. It affects other steps in the certification and accreditation process.
upvoted 2 times
...
oudmaster
1 year, 11 months ago
For me: B sounds technical perspective answer C sounds business perspective answer
upvoted 2 times
...
SongOTD
2 years, 1 month ago
Selected Answer: B
As per 6. DURING WHICH PHASE OF THE SYSTEM DEVELOPMENT LIFE CYCLE SHOULD A NEW SYSTEM BE CATEGORIZED? in here https://csrc.nist.gov/csrc/media/projects/risk-management/documents/categorize/faq-categorize-step1.pdf I would go with B.
upvoted 1 times
...
Vino22
2 years, 1 month ago
for me D, sounds better., as it fullfil the integration of security from beginning.
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...