CGRC Control Selection 5 — Questions and Answers
Question 1: An organization operating a moderate-impact system discovers that a required baseline control is technically infeasible due to a legacy hardware constraint. According to NIST SP 800-37, what is the MOST appropriate course of action?
- Remove the control from the system security plan without further documentation
- Document the infeasibility and implement a compensating control with equivalent protection (Correct answer)
- Upgrade all legacy hardware immediately before proceeding with authorization
- Request a permanent waiver from the authorizing official and discontinue control tracking
Correct answer: Document the infeasibility and implement a compensating control with equivalent protection
When a baseline control is technically infeasible, organizations should document the rationale and implement compensating controls that provide equivalent or comparable protection. This satisfies the intent of the control while acknowledging real-world constraints. Simply removing a control without alternatives or requesting a blanket waiver does not maintain the required security posture.
Question 2: During control selection for a cloud-hosted federal system, the system owner identifies several controls already implemented by the cloud service provider (CSP). How should these controls be classified in the system security plan?
- System-specific controls, because the system owner retains ultimate responsibility
- Inherited controls, because they are provided and managed by the CSP as a common control provider (Correct answer)
- Hybrid controls, regardless of who manages them, to ensure full accountability
- Excluded controls, since CSP-managed controls fall outside the system boundary
Correct answer: Inherited controls, because they are provided and managed by the CSP as a common control provider
Controls implemented and managed by the cloud service provider on behalf of tenant systems are classified as inherited (common) controls. The CSP acts as the common control provider, and the system owner inherits the protection those controls provide. This distinction is essential for accurate control responsibility mapping in the SSP.
Question 3: A risk assessment reveals that a HIGH-impact system's selected control baseline does not adequately address an emerging threat specific to the organization's mission environment. What tailoring action should the security engineer take?
- Switch the system to a MODERATE baseline to reduce the control burden
- Augment the baseline by adding supplemental controls to address the identified threat (Correct answer)
- Document the threat in the POA&M and defer remediation to the next authorization cycle
- Apply scoping guidance to remove controls unrelated to the threat
Correct answer: Augment the baseline by adding supplemental controls to address the identified threat
When a baseline does not sufficiently address identified threats, organizations should augment it by selecting additional controls or control enhancements. This is a standard tailoring action defined in NIST SP 800-53B. Downgrading the baseline or deferring without action would increase residual risk beyond acceptable levels for a HIGH-impact system.
Question 4: Which NIST publication provides the catalog from which security and privacy controls are selected during the Control Selection step of the RMF?
- NIST SP 800-37 — Risk Management Framework
- NIST SP 800-30 — Guide for Conducting Risk Assessments
- NIST SP 800-53 — Security and Privacy Controls for Information Systems (Correct answer)
- NIST SP 800-60 — Guide for Mapping Types of Information to Security Categories
Correct answer: NIST SP 800-53 — Security and Privacy Controls for Information Systems
NIST SP 800-53 is the control catalog used during RMF Step 2 (Select). It provides the full set of security and privacy controls and enhancements from which organizations select and tailor controls for their systems. SP 800-37 governs the overall RMF process, SP 800-30 supports risk assessments, and SP 800-60 guides security categorization.
Question 5: An organization is selecting controls for a system that processes both Controlled Unclassified Information (CUI) and publicly available data. The security categorization resulted in a MODERATE overall impact level. Which baseline should serve as the STARTING point for control selection?
- LOW baseline, because some data is publicly available and does not require protection
- HIGH baseline, because any CUI presence mandates the highest protection level
- MODERATE baseline, tailored based on the specific characteristics of the system (Correct answer)
- No baseline — controls should be selected individually based solely on threat analysis
Correct answer: MODERATE baseline, tailored based on the specific characteristics of the system
The MODERATE impact level determined through security categorization maps directly to the MODERATE control baseline as the starting point. Tailoring then adjusts controls based on system-specific factors such as environment, threat, and mission needs. Using a LOW baseline ignores the CUI requirements, and escalating to HIGH without justification would be excessive and unsupported.
Question 6: When applying scoping considerations during control tailoring, which of the following represents a VALID reason to exclude a baseline control from a system?
- The control is expensive to implement and would exceed the project budget
- The control addresses a technology type not present in the system (e.g., wireless controls for a wired-only system) (Correct answer)
- The system owner prefers a different security approach based on personal experience
- The authorizing official has not yet reviewed the control and approval is pending
Correct answer: The control addresses a technology type not present in the system (e.g., wireless controls for a wired-only system)
Technology applicability is a recognized scoping consideration in NIST SP 800-53B. If a control is designed for a technology or capability not used in the system (such as wireless security controls for a fully wired system), it may be scoped out with proper documentation. Cost and personal preference are not valid scoping justifications, and pending AO review does not automatically exclude a control.
An organization operating a moderate-impact system discovers that a required baseline control is technically infeasible due to a legacy hardware constraint.
According to NIST SP 800-37, what is the MOST appropriate course of action?