CGRC Control Selection 2 — Questions and Answers
Question 1: During control selection for a federal information system, a security team identifies a required control from NIST SP 800-53 that is technically unfeasible due to legacy hardware constraints. What is the MOST appropriate next step according to the RMF?
- Remove the control from the security plan entirely
- Document a control tailoring decision and identify a compensating control (Correct answer)
- Escalate the issue to the Inspector General
- Defer implementation until new hardware is procured in the next fiscal cycle without documentation
Correct answer: Document a control tailoring decision and identify a compensating control
When a required control cannot be implemented due to technical or operational constraints, the RMF process allows for tailoring decisions, which must be documented in the System Security Plan (SSP). A compensating control should be identified to provide equivalent or comparable protection. Removing the control without documentation or justification violates RMF requirements, and deferring without documentation leaves an undocumented gap.
Question 2: A security engineer is evaluating whether to implement a network intrusion detection system (NIDS) as a security control. The NIDS monitors traffic but does not actively block threats. Which control type best describes this implementation?
- Preventive control
- Detective control (Correct answer)
- Corrective control
- Compensating control
Correct answer: Detective control
A network intrusion detection system that monitors and alerts but does not block traffic is a detective control. Detective controls identify and record security events after or as they occur, but do not prevent them. Preventive controls stop threats before they happen, corrective controls restore systems after an incident, and compensating controls substitute for primary controls when they cannot be implemented.
Question 3: An organization is selecting controls for a system that processes Controlled Unclassified Information (CUI) and has been assigned a MODERATE impact level. Which baseline from NIST SP 800-53 should serve as the starting point for control selection?
- Low baseline, then add controls as needed
- Moderate baseline (Correct answer)
- High baseline to ensure maximum protection
- There is no baseline — all controls must be selected individually
Correct answer: Moderate baseline
NIST SP 800-53 provides three control baselines — Low, Moderate, and High — corresponding to the system's impact level as determined through FIPS 199 categorization. A system categorized as MODERATE should begin with the Moderate baseline. Organizations then tailor this baseline by adding, removing, or modifying controls based on their specific environment, threat landscape, and operational requirements.
Question 4: A CGRC practitioner is reviewing a control that requires multi-factor authentication (MFA) for all privileged accounts. The organization currently uses a single-factor hardware token that generates a time-based one-time password (TOTP). How should this control be characterized?
- Fully satisfied, because TOTP constitutes a second factor when combined with a username
- Not satisfied, because TOTP alone is a single-factor authentication method
- Partially satisfied — a Plan of Action and Milestones (POA&M) should document the gap (Correct answer)
- Satisfied only if the privileged accounts belong to administrators, not developers
Correct answer: Partially satisfied — a Plan of Action and Milestones (POA&M) should document the gap
A username combined with a TOTP token represents something you know (username/password) plus something you have (the token), which typically constitutes two factors. However, if the organization is only using the token without a separate password, it remains single-factor. In the common implementation where a password plus TOTP is used, MFA is satisfied. If the control is not fully met — for example, if some privileged accounts are excluded — a POA&M should document the gap and remediation timeline. Given the ambiguity in the scenario about the full implementation, partial satisfaction with a POA&M is the most prudent answer.
Question 5: When applying control tailoring during the RMF Select step, which of the following actions is NOT a recognized tailoring activity per NIST SP 800-53B?
- Applying scoping considerations to eliminate controls not applicable to the system
- Adding organization-defined parameter values to controls with assignment operations
- Replacing all baseline controls with custom controls developed in-house (Correct answer)
- Supplementing the baseline with additional controls based on risk assessment findings
Correct answer: Replacing all baseline controls with custom controls developed in-house
Recognized tailoring activities in NIST SP 800-53B include applying scoping considerations, specifying parameter values for organization-defined parameters, and supplementing the baseline with additional controls when risk warrants it. Wholesale replacement of all baseline controls with custom in-house controls is not a recognized tailoring activity — the established baseline exists to ensure a minimum protection standard, and replacing it entirely would undermine the RMF's risk management framework.
Question 6: An organization operating a cloud-based system leverages its Cloud Service Provider's (CSP) FedRAMP-authorized environment. Some security controls are managed entirely by the CSP. How should these controls be reflected in the organization's System Security Plan (SSP)?
- Omitted from the SSP since the CSP is responsible for them
- Listed as inherited controls with a reference to the CSP's authorization package (Correct answer)
- Documented as compensating controls implemented by a third party
- Marked as not applicable because the cloud boundary excludes them
Correct answer: Listed as inherited controls with a reference to the CSP's authorization package
When a customer organization leverages a FedRAMP-authorized CSP, controls that are fully managed by the CSP are documented as inherited controls in the organization's SSP. The SSP references the CSP's authorization package (e.g., their FedRAMP package) as evidence of control implementation. This inheritance model is a core concept in cloud security under the RMF — it reduces duplication of effort while maintaining accountability and traceability across organizational boundaries.
During control selection for a federal information system, a security team identifies a required control from NIST SP 800-53 that is technically unfeasible due to legacy hardware constraints.
What is the MOST appropriate next step according to the RMF?