Several encryption and access controls for a county EHR need recurring evidence from the same system owners. Which common IRM capability should the implementer rely on?
Select an answer to reveal the explanation.
Short Explanation
Attestations are like a reusable checklist clipboard you hand the same owners for different controls. One common evidence mechanism, many controls—without reinventing a survey for every row. That’s the shared attestation idea in IRM common elements.
Full Explanation
Attestations are a common IRM capability for collecting structured owner evidence and can be associated across controls rather than inventing ad-hoc proof per record. That reuse supports consistent compliance and risk assurance processes. One-off PDFs, disconnected surveys, or security incident playbooks are not the shared attestation model CIS-RC expects under common elements.