Study. uk . com
  1. Home
  2. All questions
  3. Question 79

CompTIA Security+ study material · question 79 of 611

Which artefact does an authorising official read to understand a system's control effectiveness before making the authorisation decision?

  1. The acceptable use policy
  2. The vendor's service level agreement
  3. The business impact analysis
  4. The security assessment report
Show the answer

Answer: D. The security assessment report

Assessment produces evidence, and the security assessment report is what the official weighs when accepting residual risk.

Source: NIST SP 800-37 Rev. 2 (NIST) — SP 800-37 Rev. 2 § 3.5 Assess

Challenge yourself on this topic → Study as cards