CAP Security Control Implementation 2 — Questions and Answers
Question 1: What is the primary purpose of applying security engineering principles during security control implementation?
- To reduce the total number of controls required
- To integrate security into systems from the design phase (Correct answer)
- To eliminate the need for post-implementation assessments
- To replace the System Security Plan with engineering diagrams
Correct answer: To integrate security into systems from the design phase
Security engineering principles ensure that security requirements and controls are built into systems from the beginning rather than retrofitted after development.
Question 2: When a system owner inherits a common control from an external provider, what responsibility does the system owner retain?
- Reimplementing the control independently within their system
- Verifying the inherited control adequately satisfies their system's security requirements (Correct answer)
- Conducting a separate formal assessment of the inherited control
- Accepting all residual risk generated by the common control provider
Correct answer: Verifying the inherited control adequately satisfies their system's security requirements
System owners must verify that inherited controls are appropriately implemented and actually satisfy the security requirements for their specific system.
Question 3: According to NIST SP 800-53, which control baseline applies to an information system with a FIPS 199 overall impact level of Moderate?
- Low baseline
- Moderate baseline (Correct answer)
- High baseline
- Minimum security baseline
Correct answer: Moderate baseline
NIST SP 800-53 directly maps baseline selection to impact level, so a Moderate-impact system uses the Moderate security control baseline.
Question 4: What is the purpose of security control overlays in the implementation process?
- To reduce the number of required security assessors
- To tailor baseline controls for specific technologies, environments, or communities of interest (Correct answer)
- To replace the need for security categorization
- To eliminate inherited controls from the SSP
Correct answer: To tailor baseline controls for specific technologies, environments, or communities of interest
Overlays provide tailoring guidance that customizes security control baselines for specific technologies, deployment environments, or sector-specific requirements.
Question 5: Which concept BEST describes implementing multiple overlapping layers of security controls to protect information system resources?
- Least privilege
- Defense in depth (Correct answer)
- Separation of duties
- Need to know
Correct answer: Defense in depth
Defense in depth involves layering multiple security controls so that if one control fails, additional controls remain in place to protect the system.
Question 6: During implementation, who is primarily responsible for ensuring that security controls are correctly configured and operational in the information system?
- The Authorizing Official (AO)
- The Information System Security Officer (ISSO)
- The System Owner (Correct answer)
- The Security Control Assessor (SCA)
Correct answer: The System Owner
The System Owner has primary accountability for ensuring security controls are properly implemented and operational in accordance with the System Security Plan.
Question 7: What is a 'security control baseline' as defined in NIST SP 800-53?
- The initial set of controls corresponding to a system's impact level before tailoring (Correct answer)
- The final set of controls remaining after a security assessment
- A list of controls verified as effective during continuous monitoring
- Controls that apply universally to all federal systems regardless of impact level
Correct answer: The initial set of controls corresponding to a system's impact level before tailoring
A security control baseline is the starting set of controls mapped to a system's impact level (Low, Moderate, or High), which is then tailored to meet specific organizational needs.
What is the primary purpose of applying security engineering principles during security control implementation?