CAP Information Security Continuous Monitoring (ISCM) Strategy & Implementation — Questions and Answers
Question 1: Which NIST publication specifically provides guidance for developing an Information Security Continuous Monitoring (ISCM) program?
- NIST SP 800-37
- NIST SP 800-53
- NIST SP 800-137 (Correct answer)
- NIST SP 800-171
Correct answer: NIST SP 800-137
NIST SP 800-137 ('Information Security Continuous Monitoring for Federal Information Systems and Organizations') provides guidance for developing an ISCM strategy, defining metrics, establishing monitoring frequencies, and reporting security status to organizational officials.
Question 2: NIST SP 800-137 defines three tiers for ISCM. Which set correctly identifies these tiers?
- Strategic, Operational, Tactical
- Organization, Mission/Business Process, Information System (Correct answer)
- Executive, Management, Technical
- Policy, Process, Procedure
Correct answer: Organization, Mission/Business Process, Information System
NIST SP 800-137 aligns ISCM to the three-tiered risk management hierarchy from NIST SP 800-39: Tier 1 (Organization), Tier 2 (Mission/Business Process), and Tier 3 (Information System). Each tier has distinct ISCM roles and responsibilities.
Question 3: In the context of ISCM, what does 'ongoing authorization' mean?
- The AO issues a permanent ATO that never requires renewal.
- Security status is monitored continuously, allowing the AO to make risk acceptance decisions in near real-time rather than at fixed three-year intervals. (Correct answer)
- New systems are granted authorization automatically if they pass an initial scan.
- The ISSO re-authorizes the system every 30 days without AO involvement.
Correct answer: Security status is monitored continuously, allowing the AO to make risk acceptance decisions in near real-time rather than at fixed three-year intervals.
Ongoing authorization replaces the traditional fixed three-year reauthorization cycle. By continuously monitoring security controls and reporting status, the AO maintains current situational awareness and can make risk decisions based on near real-time security posture rather than a point-in-time assessment.
Question 4: Which of the following is the FIRST step in the NIST SP 800-137 ISCM process?
- Analyze data and report findings.
- Define an ISCM strategy. (Correct answer)
- Implement the monitoring program.
- Respond to findings with corrective actions.
Correct answer: Define an ISCM strategy.
The NIST SP 800-137 ISCM process follows six steps: (1) Define, (2) Establish, (3) Implement, (4) Analyze/Report, (5) Respond, (6) Review/Update. Defining the ISCM strategy — including scope, metrics, and frequencies — is the mandatory first step.
Question 5: What is the role of 'security metrics' in an ISCM program?
- Metrics are used solely for annual budget justification to leadership.
- Metrics provide quantifiable measures of security control effectiveness and organizational security posture over time. (Correct answer)
- Metrics replace the need for human security analysts in the monitoring process.
- Metrics are only required for HIGH-impact systems under FISMA.
Correct answer: Metrics provide quantifiable measures of security control effectiveness and organizational security posture over time.
In ISCM, security metrics are quantifiable measures used to assess the effectiveness of security controls and track the organization's security posture over time. They enable data-driven risk decisions by the AO and support the ongoing authorization model.
Question 6: An organization's ISCM program detects that a critical security control has become ineffective due to a configuration change. What is the appropriate ISCM response action?
- Wait until the next annual assessment to document the finding.
- Immediately revoke the system's ATO without notifying the System Owner.
- Analyze the impact on risk, report to the AO, and initiate remediation per the POA&M process. (Correct answer)
- Disable the affected system until the next scheduled maintenance window.
Correct answer: Analyze the impact on risk, report to the AO, and initiate remediation per the POA&M process.
When ISCM detects a control deficiency, the process requires: analyzing the risk impact, reporting the finding to the Authorizing Official with current security posture information, and initiating corrective action through the POA&M process. The AO then decides whether to continue operations, impose restrictions, or revoke authorization.
Which NIST publication specifically provides guidance for developing an Information Security Continuous Monitoring (ISCM) program?