Study. uk . com
  1. Home
  2. All questions
  3. Question 15

CompTIA Security+ study material · question 15 of 611

An organisation wants to move from three-yearly reauthorisation to ongoing authorisation. Which capability makes that possible?

  1. An annual penetration test
  2. A signed acceptable use policy
  3. Continuous monitoring of control effectiveness
  4. A larger control baseline
Show the answer

Answer: C. Continuous monitoring of control effectiveness

Ongoing authorisation rests on continuous monitoring evidence rather than a periodic full reassessment.

Source: NIST SP 800-37 Rev. 2 (NIST) — SP 800-37 Rev. 2 § 3.7 Monitor

Challenge yourself on this topic → Study as cards