組織では、1 つの集中型シングル サインオン (SSO) コントロールを使用して、多数のアプリケーションをカバーしています。SSO コントロールのテストが完了した後に新しいアプリケーションが環境に追加された場合、次のうちどれが最善の対応策でしょうか。
正解:A
The best course of action when a new application is added to the environment after testing of the SSO control has been completed is to initiate a retest of the full control, as it may reveal any new issues or gaps that the new application may introduce to the SSO control, and ensure that the control remains effective and adequate.
Retesting the control using the new application as the only sample, reviewing the corresponding change control documentation, and re-evaluating the control during the next assessment are not the best courses of action, as they may not provide sufficient assurance, evidence, or timeliness of the control testing, respectively. References = CRISC Review Manual, 7th Edition, page 154.