Information Security Continuous Monitoring (ISCM) Strategy & Implementation Flashcards
6 cards from real CAP practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 6 Information Security Continuous Monitoring (ISCM) Strategy & Implementation flashcards as text
Which NIST publication specifically provides guidance for developing an Information Security Continuous Monitoring (ISCM) program?
Answer: NIST SP 800-137
NIST SP 800-137 ('Information Security Continuous Monitoring for Federal Information Systems and Organizations') provides guidance for developing an ISCM strategy, defining metrics, establishing monitoring frequencies, and reporting security status to organizational officials.
NIST SP 800-137 defines three tiers for ISCM. Which set correctly identifies these tiers?
Answer: Organization, Mission/Business Process, Information System
NIST SP 800-137 aligns ISCM to the three-tiered risk management hierarchy from NIST SP 800-39: Tier 1 (Organization), Tier 2 (Mission/Business Process), and Tier 3 (Information System). Each tier has distinct ISCM roles and responsibilities.
In the context of ISCM, what does 'ongoing authorization' mean?
Answer: Security status is monitored continuously, allowing the AO to make risk acceptance decisions in near real-time rather than at fixed three-year intervals.
Ongoing authorization replaces the traditional fixed three-year reauthorization cycle. By continuously monitoring security controls and reporting status, the AO maintains current situational awareness and can make risk decisions based on near real-time security posture rather than a point-in-time assessment.
Which of the following is the FIRST step in the NIST SP 800-137 ISCM process?
Answer: Define an ISCM strategy.
The NIST SP 800-137 ISCM process follows six steps: (1) Define, (2) Establish, (3) Implement, (4) Analyze/Report, (5) Respond, (6) Review/Update. Defining the ISCM strategy — including scope, metrics, and frequencies — is the mandatory first step.
What is the role of 'security metrics' in an ISCM program?
Answer: Metrics provide quantifiable measures of security control effectiveness and organizational security posture over time.
In ISCM, security metrics are quantifiable measures used to assess the effectiveness of security controls and track the organization's security posture over time. They enable data-driven risk decisions by the AO and support the ongoing authorization model.
An organization's ISCM program detects that a critical security control has become ineffective due to a configuration change. What is the appropriate ISCM response action?
Answer: Analyze the impact on risk, report to the AO, and initiate remediation per the POA&M process.
When ISCM detects a control deficiency, the process requires: analyzing the risk impact, reporting the finding to the Authorizing Official with current security posture information, and initiating corrective action through the POA&M process. The AO then decides whether to continue operations, impose restrictions, or revoke authorization.