ISC2 CISSP (Certified Information Systems Security Professional)Security Assessment and TestingMedium
A security assessment reveals that an organization's incident response plan has never been tested in a simulated environment. The plan outlines clear steps for incident detection, analysis, containment, eradication, recovery, and post-incident review. However, without actual testing, the effectiveness of these steps and the team's ability to execute them under pressure are unknown. This represents a gap in which aspect of the security program?
- ACompliance auditing
- BSecurity policy development
- CSecurity control validation
- DSecurity awareness training
Show answer & explanationAnswer & explanation
Correct answer: C. Security control validation
The scenario describes a plan that exists but whose effectiveness and executability are 'unknown' due to lack of testing. This directly points to a failure in validating whether a control (the incident response plan) actually works as intended.
Why the other options are wrong
- A. Compliance auditing checks adherence to rules, but validation goes further to ensure functional effectiveness.
- B. Policy development refers to creating the plan, which exists here.
- D. Awareness training ensures personnel know policies, but doesn't validate the plan's functional effectiveness.
Security Control Validation
The process of testing and evaluating security controls to ensure they are implemented correctly, operating as intended, and achieving their desired security objectives.
- Confirms controls are effective
- Includes testing, simulations, and exercises
- Identifies gaps between design and actual performance
Memory trick: Gaps: Policy, Training, or Unvalidated Controls.