CISSP Exam QuestionsBrowse all questions from this exam

CISSP Exam - Question 290


Which of the following is a term used to describe maintaining ongoing awareness of information security, vulnerabilities, and threats to support organizational risk management decisions?

Show Answer
Correct Answer: A

Information Security Continuous Monitoring (ISCM) is defined as maintaining ongoing awareness of information security, vulnerabilities, and threats to support organizational risk management decisions. This process involves the systematic monitoring of security controls and organizational risks to ensure they are managed effectively and are sufficient to protect the organization's information.

Discussion

5 comments
Sign in to comment
JAckThePipOption: A
Oct 5, 2022

Answer is correct "Maintaining ongoing awareness of information security, vulnerabilities, and threats to support organizational risk management decisions. Note: The terms “continuous” and “ongoing” in this context mean that security controls and organizational risks are assessed and analyzed at a frequency sufficient to support risk-based security decisions to adequately protect organization information. See organizational information security continuous monitoring and automated security monitoring." https://csrc.nist.gov/glossary/term/information_security_continuous_monitoring

RVoigtOption: A
Jan 10, 2023

Information security continuous monitoring (ISCM) is defined as maintaining ongoing awareness of information security, vulnerabilities, and threats to support organizational risk management decisions. https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-137.pdf

jackdryan
May 13, 2023

A is correct

janvandermerwerOption: A
Aug 1, 2023

A. Information Security Continuous Monitoring (ISCM)

SoleandheelOption: A
Dec 14, 2023

A. Information Security Continuous Monitoring (ISCM)

CCNPWILLOption: A
May 1, 2024

A. Continous is ongoing.