CAP Security Control Selection, Tailoring & Baselines (NIST SP 800-53) — Questions and Answers
Question 1: A federal system is categorized as MODERATE impact. Which NIST SP 800-53 security control baseline should be applied as the starting point?
- The LOW baseline, then augmented as needed.
- The MODERATE baseline. (Correct answer)
- The HIGH baseline, then scoped down.
- No baseline — controls are selected individually for each system.
Correct answer: The MODERATE baseline.
NIST SP 800-53 defines three control baselines (LOW, MODERATE, HIGH) aligned to FIPS 199 impact levels. A MODERATE-categorized system uses the MODERATE baseline as its starting point before any tailoring.
Question 2: Which tailoring action allows an organization to remove a security control from the baseline because it is not applicable to the system's operating environment?
- Supplementation
- Overlay application
- Scoping (Correct answer)
- Compensating control substitution
Correct answer: Scoping
Scoping involves applying specific guidance to adjust the baseline — including eliminating controls that are not applicable (e.g., removing mobile device controls from a system that has no mobile interfaces). Supplementation adds controls; overlays are community-wide tailoring guidance; compensating controls substitute when a baseline control cannot be implemented.
Question 3: An organization cannot implement a required NIST SP 800-53 control due to a documented technical constraint. What is the correct approach?
- Remove the control from the Security Plan without documentation.
- Implement a compensating control that provides equivalent protection, and document it. (Correct answer)
- Accept the risk without any alternative measure.
- Escalate to NIST for a waiver of the control requirement.
Correct answer: Implement a compensating control that provides equivalent protection, and document it.
When a required control cannot be implemented, organizations should identify and implement a compensating control that provides equivalent or comparable protection. This must be documented in the Security Plan and approved by the Authorizing Official.
Question 4: Which of the following best describes a 'security control overlay' in NIST SP 800-53?
- A custom baseline created by an individual organization for its own internal use.
- A community-wide tailoring of the security control catalog for a specific technology type, environment, or mission. (Correct answer)
- An additional layer of encryption applied on top of existing security controls.
- The process of mapping controls from one framework (e.g., ISO 27001) to NIST SP 800-53.
Correct answer: A community-wide tailoring of the security control catalog for a specific technology type, environment, or mission.
Overlays are tailored baselines developed for specific communities of interest (e.g., cloud systems, healthcare, Industrial Control Systems). They adjust the baseline controls to reflect the unique requirements of that environment and are approved for community-wide use.
Question 5: In NIST SP 800-53, security controls are organized into 'families.' Which control family specifically addresses planning for security activities?
- Risk Assessment (RA)
- Program Management (PM)
- Planning (PL) (Correct answer)
- System and Services Acquisition (SA)
Correct answer: Planning (PL)
The Planning (PL) family in NIST SP 800-53 includes controls related to security planning activities, such as developing the System Security Plan (SSP) and Rules of Behavior. The PL family is directly relevant to the authorization documentation process.
Question 6: What is the purpose of 'supplementation' during security control tailoring?
- To remove inapplicable controls from the baseline.
- To add controls beyond the baseline to address residual risks or organizational policies. (Correct answer)
- To replace all baseline controls with organizational-specific alternatives.
- To document which controls were inherited from a common control provider.
Correct answer: To add controls beyond the baseline to address residual risks or organizational policies.
Supplementation is the tailoring action of adding controls (or control enhancements) to the baseline to address risks not adequately covered by baseline controls, or to meet specific organizational or mission requirements. It is the opposite of scoping, which removes controls.
A federal system is categorized as MODERATE impact.
Which NIST SP 800-53 security control baseline should be applied as the starting point?