CGRC CGRC Information Security Controls 1 — Questions and Answers
Question 1: Which NIST publication provides a catalog of security and privacy controls for federal information systems?
- NIST SP 800-37
- NIST SP 800-53 (Correct answer)
- NIST SP 800-30
- NIST SP 800-60
Correct answer: NIST SP 800-53
NIST SP 800-53 provides the catalog of security and privacy controls used to protect federal information systems.
Question 2: In the context of CGRC, what is the primary purpose of a security control baseline?
- To document all known vulnerabilities
- To provide a starting set of controls for a given impact level (Correct answer)
- To record audit findings
- To define network perimeter boundaries
Correct answer: To provide a starting set of controls for a given impact level
A security control baseline provides a pre-defined set of minimum controls selected based on the system's impact level (Low, Moderate, or High).
Question 3: Which control family in NIST SP 800-53 addresses identification and authentication requirements?
- AC – Access Control
- IA – Identification and Authentication (Correct answer)
- SI – System and Information Integrity
- AU – Audit and Accountability
Correct answer: IA – Identification and Authentication
The IA (Identification and Authentication) control family addresses requirements for uniquely identifying and authenticating users and devices.
Question 4: What term describes the process of selecting and adjusting security controls to meet the specific needs of an organization or system?
- Control inheritance
- Control tailoring (Correct answer)
- Control authorization
- Control scoping
Correct answer: Control tailoring
Tailoring is the process of modifying a baseline by adding, removing, or adjusting controls to fit the system's specific environment and risk profile.
Question 5: Which type of control is implemented through hardware, software, or firmware to protect information systems?
- Administrative control
- Physical control
- Technical control (Correct answer)
- Operational control
Correct answer: Technical control
Technical controls (also called logical controls) use technology such as encryption, firewalls, and access control software to protect systems.
Question 6: Under NIST SP 800-53, which control family specifically addresses planning for security activities within a system?
- PM – Program Management
- PL – Planning (Correct answer)
- SA – System and Services Acquisition
- CA – Assessment, Authorization, and Monitoring
Correct answer: PL – Planning
The PL (Planning) control family covers system security plans and related planning activities required for FISMA compliance.
Which NIST publication provides a catalog of security and privacy controls for federal information systems?