CGRC CGRC Information Security Controls 2 — Questions and Answers
Question 1: What is the purpose of a System Security Plan (SSP) in the RMF process?
- To document the results of penetration testing
- To describe the security requirements and controls implemented for a system (Correct answer)
- To outline the organization's disaster recovery procedures
- To list all approved software for installation
Correct answer: To describe the security requirements and controls implemented for a system
An SSP formally documents a system's security requirements, the controls selected to meet those requirements, and the roles responsible for implementation.
Question 2: Which concept refers to a system's ability to inherit security controls implemented by a common control provider?
- Control aggregation
- Control inheritance (Correct answer)
- Control delegation
- Control abstraction
Correct answer: Control inheritance
Control inheritance allows a system to leverage and rely on controls already implemented by a shared infrastructure or service provider without re-implementing them.
Question 3: What is a compensating control?
- A control that exceeds baseline requirements
- An alternative control used when the required control cannot be implemented (Correct answer)
- A control applied only during incident response
- A control that monitors the effectiveness of other controls
Correct answer: An alternative control used when the required control cannot be implemented
A compensating control provides equivalent protection when the primary required control cannot be implemented due to technical or operational constraints.
Question 4: Which FIPS standard is used to categorize federal information and information systems based on potential impact?
- FIPS 140-3
- FIPS 200
- FIPS 199 (Correct answer)
- FIPS 186-5
Correct answer: FIPS 199
FIPS 199 defines the standards for categorizing information and information systems as Low, Moderate, or High based on confidentiality, integrity, and availability impacts.
Question 5: In NIST SP 800-53, what does the CM control family address?
- Contingency Management
- Configuration Management (Correct answer)
- Change Monitoring
- Compliance Measurements
Correct answer: Configuration Management
The CM (Configuration Management) family includes controls for establishing and maintaining baseline configurations and tracking changes to systems.
Question 6: What is the role of the System Owner in relation to security controls under the RMF?
- Authorizing system operation based on residual risk
- Ensuring controls are implemented, documented, and maintained for their system (Correct answer)
- Conducting independent security assessments
- Providing legal authority for data processing
Correct answer: Ensuring controls are implemented, documented, and maintained for their system
The System Owner is responsible for ensuring that security controls are properly implemented, documented in the SSP, and kept current throughout the system lifecycle.
What is the purpose of a System Security Plan (SSP) in the RMF process?