CGRC Control Selection 1 — Questions and Answers
Question 1: An organization is implementing a new cloud-based payroll system that processes sensitive employee data. During control selection, the security team must choose between implementing a hardware security module (HSM) or software-based encryption. Which NIST SP 800-53 control family is MOST directly relevant to this decision?
- Access Control (AC)
- System and Communications Protection (SC) (Correct answer)
- Audit and Accountability (AU)
- Configuration Management (CM)
Correct answer: System and Communications Protection (SC)
System and Communications Protection (SC) directly governs cryptographic protection mechanisms, including encryption of data in transit and at rest. SC controls address the use of cryptographic modules (like HSMs) and encryption algorithms to protect sensitive information, making it the most relevant control family for this decision.
Question 2: A federal agency is selecting controls for a moderate-impact system. The system owner wants to add a biometric authentication control that is not in the NIST SP 800-53 baseline. What is the correct term for this type of control addition?
- Control enhancement
- Compensating control
- Supplemental control (Correct answer)
- Inherited control
Correct answer: Supplemental control
When an organization adds controls beyond the baseline to address specific threats or risks not fully mitigated by the baseline, these are called supplemental controls. Supplemental controls are selected based on risk assessment findings and organizational needs beyond what the standard baseline requires.
Question 3: During control selection, a system owner discovers that implementing the required physical access control for a remote server closet would cost $200,000, while the asset being protected is valued at $50,000. Which principle should guide the control selection decision in this scenario?
- Defense in depth
- Least privilege
- Cost-benefit analysis (Correct answer)
- Risk transference
Correct answer: Cost-benefit analysis
Cost-benefit analysis is a foundational principle in control selection that ensures the cost of implementing a control does not exceed the value of the asset being protected or the potential loss from a risk. In this case, spending $200,000 to protect a $50,000 asset is not economically justified, and alternative controls should be considered.
Question 4: A CGRC practitioner is reviewing the System Security Plan (SSP) and notices that some controls are marked as 'inherited' from a common control provider. What does inheriting a control mean in the context of the RMF?
- The system owner must re-implement the control locally to verify it works
- The system receives the security capability from an external provider and does not need to re-implement it (Correct answer)
- The control has been waived and does not apply to the system
- The control must be enhanced before it can be applied to the system
Correct answer: The system receives the security capability from an external provider and does not need to re-implement it
In the RMF, inheriting a control means the system leverages a security capability already implemented by a common control provider (e.g., a data center's physical security or a shared authentication service). The inheriting system documents this in its SSP and relies on the provider's authorization rather than re-implementing the control itself.
Question 5: An organization is selecting controls for a HIGH-impact system under NIST SP 800-53. Which document provides the STARTING POINT for selecting the initial control baseline?
- NIST SP 800-37 (RMF)
- NIST SP 800-53B (Control Baselines) (Correct answer)
- NIST SP 800-30 (Risk Assessment)
- FIPS 199 (Security Categorization)
Correct answer: NIST SP 800-53B (Control Baselines)
NIST SP 800-53B provides the control baselines — LOW, MODERATE, and HIGH — that serve as the starting point for control selection. Once the system is categorized (using FIPS 199), practitioners turn to SP 800-53B to identify the appropriate baseline, which is then tailored based on risk assessment results and organizational factors.
Question 6: A security team is tailoring the HIGH baseline for a financial system and decides to remove the SC-8 (Transmission Confidentiality and Integrity) control because all data transfers occur on a physically isolated network. What RMF process step does this represent?
- Control scoping (Correct answer)
- Control compensation
- Control inheritance
- Control monitoring
Correct answer: Control scoping
Tailoring includes scoping considerations, which allow organizations to apply baseline controls in a targeted manner or exclude controls that are not applicable given specific operational or technical conditions. Removing SC-8 because the network is physically isolated is a scoping decision — the threat the control addresses is mitigated by the environment, making the control not applicable.
An organization is implementing a new cloud-based payroll system that processes sensitive employee data.
During control selection, the security team must choose between implementing a hardware security module (HSM) or software-based encryption.
Which NIST SP 800-53 control family is MOST directly relevant to this decision?