CGRC Control Selection 4 — Questions and Answers
Question 1: A security engineer is reviewing the control baseline for a new cloud-hosted financial system. The system processes highly sensitive PII and is categorized as HIGH impact. Which NIST SP 800-53 baseline should serve as the STARTING POINT for control selection?
- LOW baseline, then add controls based on threat modeling
- MODERATE baseline, since most federal systems use it by default
- HIGH baseline, tailored further based on system-specific risk factors (Correct answer)
- A custom baseline built from scratch without referencing existing baselines
Correct answer: HIGH baseline, tailored further based on system-specific risk factors
NIST RMF guidance specifies that the initial control baseline is selected based on the system's impact level. A HIGH-impact system starts with the HIGH baseline from NIST SP 800-53B. Organizations then tailor that baseline — adding, removing, or modifying controls — based on specific risk factors, but always starting from the appropriate impact-level baseline.
Question 2: During Step 3 (Select) of the NIST RMF, an organization identifies that several HIGH-baseline controls are not applicable because the system has no external network connectivity. What tailoring action is appropriate?
- Compensating control implementation to address the control gap
- Scoping the controls out as not applicable based on the system's operational environment (Correct answer)
- Upgrading the system to include network connectivity so controls apply
- Documenting the gap and accepting residual risk without any tailoring action
Correct answer: Scoping the controls out as not applicable based on the system's operational environment
Scoping is a tailoring action that allows organizations to exclude controls that are not applicable given the system's environment, technology, or operational constraints. When a system lacks external network connectivity, network-related controls may be legitimately scoped out. This is distinct from compensating controls, which substitute an equivalent control when the original cannot be implemented.
Question 3: An organization cannot implement a required cryptographic control due to a legacy system limitation. The system owner proposes an alternative measure — increased physical security and strict access controls — to reduce equivalent risk. What is this called?
- Control enhancement
- Risk transference
- Compensating control (Correct answer)
- Supplemental control
Correct answer: Compensating control
A compensating control is an alternative security measure put in place when a required control cannot be implemented due to technical, operational, or other constraints. The compensating control must provide equivalent or comparable protection. In this case, enhanced physical security and strict access controls are used to compensate for the inability to implement cryptographic controls on a legacy system.
Question 4: Which document formally captures the selected controls, tailoring decisions, and planned implementation details for an information system during the NIST RMF Select step?
- Plan of Action and Milestones (POA&M)
- System Security Plan (SSP) (Correct answer)
- Security Assessment Report (SAR)
- Authorization to Operate (ATO)
Correct answer: System Security Plan (SSP)
The System Security Plan (SSP) is the primary document produced and updated during Step 3 (Select) of the RMF. It documents the system boundary, control baseline, tailoring decisions, control implementation descriptions, and responsibilities. The POA&M tracks remediation of weaknesses; the SAR documents assessment findings; the ATO is the authorization decision itself.
Question 5: A CGRC practitioner is advising on control selection for a system shared by multiple programs within an agency. Several of the required controls are already implemented at the organizational level and maintained by a central team. How should these be treated?
- Re-implement them at the system level to ensure layered defense
- Inherited as common controls, referencing the providing system's SSP (Correct answer)
- Documented as compensating controls in the system's POA&M
- Removed from the system's control baseline since they are redundant
Correct answer: Inherited as common controls, referencing the providing system's SSP
Common controls are controls that are implemented at an organizational, site, or program level and inherited by multiple systems. When a system can inherit a control from a common control provider, it should document this inheritance in its SSP, referencing the authoritative source. This avoids duplication of effort and leverages centrally managed security capabilities. Common controls must be documented and authorized, not simply assumed.
Question 6: When performing control tailoring, an organization adds additional controls beyond the baseline to address a specific, identified threat related to insider privilege abuse. What is this tailoring action called?
- Scoping
- Parameterization
- Control supplementation (Correct answer)
- Baseline substitution
Correct answer: Control supplementation
Control supplementation involves adding controls or control enhancements to a baseline to address specific threats, vulnerabilities, or risks that are not adequately covered by the baseline alone. In this case, insider threat concerns drive the addition of controls beyond what the standard HIGH baseline provides. Scoping removes non-applicable controls; parameterization assigns specific values to control parameters; baseline substitution is not a recognized NIST tailoring action.
A security engineer is reviewing the control baseline for a new cloud-hosted financial system.
The system processes highly sensitive PII and is categorized as HIGH impact.
Which NIST SP 800-53 baseline should serve as the STARTING POINT for control selection?