CGRC Control Selection 3 — Questions and Answers
Question 1: A security engineer is selecting controls for a system that processes Controlled Unclassified Information (CUI) for a federal agency. Which NIST publication provides the baseline control catalog they should start with?
- NIST SP 800-53 (Correct answer)
- NIST SP 800-37
- NIST SP 800-171
- NIST SP 800-60
Correct answer: NIST SP 800-53
NIST SP 800-53 provides the comprehensive catalog of security and privacy controls for federal information systems and organizations. While SP 800-171 derives from SP 800-53 and applies to CUI in non-federal systems, the primary control catalog for federal agencies is SP 800-53. SP 800-37 covers the Risk Management Framework process, and SP 800-60 maps information types to security categories.
Question 2: During control selection, an organization determines that implementing a required baseline control would cost $500,000 annually but only protects against a risk with an expected loss of $50,000 per year. What is the most appropriate course of action?
- Implement the control regardless, as baseline controls are mandatory
- Document a risk acceptance decision and seek authorization to waive the control
- Apply for a control tailoring adjustment, potentially replacing it with a compensating control or adjusting implementation (Correct answer)
- Ignore the control since the cost outweighs the benefit
Correct answer: Apply for a control tailoring adjustment, potentially replacing it with a compensating control or adjusting implementation
Tailoring allows organizations to adjust baseline controls based on organizational conditions, operational environments, and risk assessments. When a control is cost-prohibitive relative to the risk it mitigates, the organization should use the tailoring process — which may include scoping guidance, substituting compensating controls, or documenting the rationale — rather than blindly implementing or ignoring the control. This must be documented and approved by the authorizing official.
Question 3: Which factor is considered FIRST when determining the appropriate security control baseline for a federal information system?
- The system's interconnections with other federal systems
- The FIPS 199 security categorization of the system (Correct answer)
- The organization's available budget for security controls
- The number of users accessing the system
Correct answer: The FIPS 199 security categorization of the system
The FIPS 199 security categorization — which determines whether a system is Low, Moderate, or High impact based on confidentiality, integrity, and availability — is the primary driver for selecting the initial control baseline. A Low impact system uses the SP 800-53B Low baseline, Moderate uses the Moderate baseline, and High uses the High baseline. Budget, interconnections, and user count may influence tailoring decisions afterward, but categorization comes first.
Question 4: An organization is selecting controls for a cloud-hosted system and needs to determine which controls are the responsibility of the cloud service provider (CSP) versus the agency. Which document formalizes this division of control responsibilities?
- System Security Plan (SSP)
- Plan of Action and Milestones (POA&M)
- Customer Responsibility Matrix (CRM) or shared responsibility agreement (Correct answer)
- Security Assessment Report (SAR)
Correct answer: Customer Responsibility Matrix (CRM) or shared responsibility agreement
A Customer Responsibility Matrix (CRM) — sometimes called a shared responsibility matrix or control responsibility matrix — formally documents which controls are implemented by the cloud service provider, which are the customer's responsibility, and which are shared. This is a critical artifact in cloud environments and is often provided by FedRAMP-authorized CSPs. The SSP documents the controls but relies on the CRM to define ownership in inherited control scenarios.
Question 5: When applying scoping considerations during control selection, an organization determines that a particular control applies to physical and environmental protection but their system is entirely cloud-based with no physical infrastructure. What scoping guidance applies?
- The control must still be fully implemented by the organization
- The control can be designated as 'Not Applicable' with documented rationale, or inherited from the CSP (Correct answer)
- The control should be deferred to the next assessment cycle
- The control must be replaced with three compensating controls
Correct answer: The control can be designated as 'Not Applicable' with documented rationale, or inherited from the CSP
Scoping considerations in NIST SP 800-53B allow organizations to designate controls as Not Applicable when they are not relevant to the system's operational environment — provided the rationale is documented in the SSP. For physical controls in a cloud environment, these are typically inherited from the cloud service provider's FedRAMP authorization package rather than implemented independently. This is a legitimate and common application of scoping guidance.
Question 6: A CGRC practitioner is helping an organization select compensating controls after determining that a required control cannot be implemented due to a legacy system constraint. Which criteria must compensating controls satisfy?
- They must be cheaper to implement than the original control
- They must provide equivalent protection and be documented with a clear rationale tied to the original control's intent (Correct answer)
- They must be selected from the same control family as the original control
- They must be approved by NIST before being applied
Correct answer: They must provide equivalent protection and be documented with a clear rationale tied to the original control's intent
Compensating controls must provide equivalent or comparable protection to the original control they replace, and the selection must be accompanied by documented rationale explaining why the original control could not be implemented and how the compensating control achieves the same security objective. They do not need to come from the same control family, be pre-approved by NIST, or necessarily be cheaper — cost is not the deciding factor; equivalence of protection is.
A security engineer is selecting controls for a system that processes Controlled Unclassified Information (CUI) for a federal agency.
Which NIST publication provides the baseline control catalog they should start with?