CAP Security Control Implementation 1 — Questions and Answers
Question 1: What document serves as the primary guide for implementing security controls in an information system?
- Privacy Impact Assessment (PIA)
- System Security Plan (SSP) (Correct answer)
- Security Assessment Report (SAR)
- Plan of Action and Milestones (POA&M)
Correct answer: System Security Plan (SSP)
The System Security Plan documents how security controls are planned and implemented, serving as the authoritative reference for control implementation.
Question 2: Which NIST publication provides the comprehensive catalog of security and privacy controls for federal information systems?
- NIST SP 800-37
- NIST SP 800-53 (Correct answer)
- NIST SP 800-60
- FIPS 199
Correct answer: NIST SP 800-53
NIST SP 800-53 provides the catalog of security and privacy controls that organizations select from when building their control baseline.
Question 3: What type of security control is implemented centrally by an organization and inherited by multiple information systems?
- System-specific control
- Hybrid control
- Common control (Correct answer)
- Compensating control
Correct answer: Common control
Common controls are security controls whose implementation results in a capability that is inherited by one or more organizational information systems.
Question 4: When a required security control cannot be implemented as specified in the baseline, what alternative mechanism may be used with appropriate documentation?
- Residual risk acceptance
- Compensating control (Correct answer)
- Control inheritance
- Security overlay
Correct answer: Compensating control
Compensating controls are alternative management, operational, or technical safeguards employed when standard control implementation is not feasible.
Question 5: In the NIST Risk Management Framework, which step directly follows the selection of security controls?
- Assess security controls
- Authorize the information system
- Implement security controls (Correct answer)
- Monitor security controls
Correct answer: Implement security controls
The NIST RMF Step 4 (Implement) follows Step 3 (Select), requiring organizations to implement the selected controls before they can be assessed.
Question 6: What term describes a security control where implementation is split between the information system owner and a common control provider?
- Residual control
- Hybrid control (Correct answer)
- Shared control
- Overlay control
Correct answer: Hybrid control
Hybrid controls have their implementation responsibilities divided between the information system owner and a common control provider.
Question 7: Which process ensures that security controls remain correctly configured as a system evolves and changes are introduced?
- Risk assessment
- Configuration management (Correct answer)
- Incident response
- Business impact analysis
Correct answer: Configuration management
Configuration management controls changes to system components and ensures that security controls remain properly implemented as the system evolves.
What document serves as the primary guide for implementing security controls in an information system?