CGRC Continuous Monitoring 2 — Questions and Answers
Question 1: Which NIST publication provides the primary framework for implementing an Information Security Continuous Monitoring (ISCM) program?
- NIST SP 800-53
- NIST SP 800-137 (Correct answer)
- NIST SP 800-30
- NIST SP 800-39
Correct answer: NIST SP 800-137
NIST SP 800-137 specifically addresses Information Security Continuous Monitoring for federal information systems and organizations.
Question 2: What is the primary purpose of establishing monitoring frequencies in an ISCM strategy?
- To reduce the cost of security tools
- To align oversight intensity with the volatility and criticality of each control (Correct answer)
- To satisfy annual audit requirements
- To limit the volume of data collected by security systems
Correct answer: To align oversight intensity with the volatility and criticality of each control
Monitoring frequencies should be set based on how frequently a control's status can change and the impact if it fails, ensuring resources are focused where risk is highest.
Question 3: An organization discovers its automated vulnerability scanner is missing newly released CVEs because its signature database is 30 days outdated. This is an example of a failure in which ISCM component?
- Security status reporting
- Ongoing assessment
- Tool and technology management (Correct answer)
- Corrective action planning
Correct answer: Tool and technology management
Keeping scanning tools and their databases current is a tool and technology management responsibility within the ISCM program.
Question 4: In the context of continuous monitoring, what does 'ongoing authorization' mean?
- Reissuing an ATO every 90 days regardless of risk changes
- Maintaining authorization decisions current by continuously evaluating risk rather than relying solely on periodic reassessments (Correct answer)
- Requiring system owners to resubmit full authorization packages annually
- Delegating authorization decisions to automated tools
Correct answer: Maintaining authorization decisions current by continuously evaluating risk rather than relying solely on periodic reassessments
Ongoing authorization shifts from point-in-time reviews to a continuous process where the authorizing official maintains awareness of system risk at all times.
Question 5: Which metric best indicates the effectiveness of a patch management process within an ISCM program?
- Number of patches deployed per month
- Mean time to remediate critical vulnerabilities after discovery (Correct answer)
- Total number of systems scanned
- Percentage of IT budget spent on patching
Correct answer: Mean time to remediate critical vulnerabilities after discovery
Mean time to remediate (MTTR) directly measures how quickly the organization closes exploitable windows after identifying vulnerabilities.
Question 6: A security operations center (SOC) analyst notices an anomaly but has no documented escalation path. Which ISCM process element is missing?
- Automated response playbook
- Defined roles and responsibilities with escalation procedures (Correct answer)
- Threat intelligence feed integration
- Security information and event management (SIEM) tuning
Correct answer: Defined roles and responsibilities with escalation procedures
ISCM requires clearly defined roles, responsibilities, and escalation procedures so analysts know how to act when anomalies are detected.
Question 7: What distinguishes a Key Performance Indicator (KPI) from a Key Risk Indicator (KRI) in continuous monitoring?
- KPIs measure compliance while KRIs measure technical vulnerabilities
- KPIs measure how well controls are performing while KRIs signal potential future risk exposure (Correct answer)
- KPIs are reported to executives while KRIs are used only by security analysts
- KPIs apply to IT systems while KRIs apply to business processes
Correct answer: KPIs measure how well controls are performing while KRIs signal potential future risk exposure
KPIs reflect current performance of security processes, while KRIs are forward-looking signals that indicate rising risk before an incident occurs.
Which NIST publication provides the primary framework for implementing an Information Security Continuous Monitoring (ISCM) program?