CGRC Control Selection 6 — Questions and Answers
Question 1: An organization is implementing controls for a newly classified moderate-impact system. The security engineer notes that NIST SP 800-53 provides a baseline, but some controls seem unnecessary given the system's unique operating environment. What is the MOST appropriate next step?
- Implement all baseline controls exactly as specified without modification
- Tailor the control baseline by documenting justifications for any additions, removals, or modifications (Correct answer)
- Remove any controls that appear redundant and proceed to assessment
- Request a waiver from the authorizing official to skip the tailoring process
Correct answer: Tailor the control baseline by documenting justifications for any additions, removals, or modifications
Tailoring is a formal process within RMF that allows organizations to adjust the control baseline to fit their specific environment, mission, and risk tolerance. Any modifications must be documented with justifications. Simply implementing all controls without tailoring ignores legitimate organizational needs, while removing controls without documentation bypasses required governance.
Question 2: A CGRC practitioner is reviewing control selection for a federal information system. The system stores personally identifiable information (PII) and is categorized as HIGH for confidentiality. Which NIST publication provides the privacy control overlay that should be considered alongside the security control baseline?
- NIST SP 800-37
- NIST SP 800-53A
- NIST SP 800-53 Appendix J (Privacy Controls) (Correct answer)
- FIPS 199
Correct answer: NIST SP 800-53 Appendix J (Privacy Controls)
NIST SP 800-53 Appendix J contains the privacy control catalog and overlay, which provides controls specifically designed to address privacy risks associated with PII. When a system handles PII, privacy controls from this appendix must be considered alongside the security control baseline derived from the system's impact categorization.
Question 3: During control selection, a risk analyst identifies that a required baseline control would cost significantly more to implement than the potential loss from the risk it mitigates. The organization decides not to implement the control. This decision is BEST described as:
- Risk avoidance
- Risk acceptance with documented justification (Correct answer)
- Control compensation
- Risk transference
Correct answer: Risk acceptance with documented justification
When an organization consciously decides not to implement a control because the cost outweighs the benefit and accepts the residual risk, this is risk acceptance. Proper risk acceptance requires documentation and authorization from the appropriate official. Risk avoidance eliminates the activity causing the risk, compensation involves alternative controls, and transference shifts risk to another party.
Question 4: A security architect is selecting controls for a cloud-based system shared by multiple agencies. Some security controls are implemented by the cloud service provider (CSP) rather than individual agency tenants. How should inherited controls be handled in the agency's System Security Plan (SSP)?
- Inherited controls should be omitted from the SSP since the agency is not responsible for them
- The agency should duplicate and re-implement all CSP controls independently
- Inherited controls should be documented in the SSP with a reference to the authoritative source and leveraged authorization (Correct answer)
- The agency should list inherited controls only if the CSP's ATO has expired
Correct answer: Inherited controls should be documented in the SSP with a reference to the authoritative source and leveraged authorization
Inherited controls are controls implemented by an external provider (like a CSP) that an agency leverages. They must still be documented in the agency's SSP, identifying them as inherited and referencing the provider's authorization documentation (e.g., FedRAMP authorization). This ensures traceability and accountability while avoiding redundant implementation.
Question 5: An organization is selecting controls for a system that processes sensitive but unclassified information. They want to apply a community-developed set of additional controls beyond the NIST baseline for their specific industry sector. In RMF terminology, this additional set of controls is called a:
- Control enhancement
- Compensating control
- Control overlay (Correct answer)
- Scoping consideration
Correct answer: Control overlay
A control overlay is a fully specified set of controls, control enhancements, or supplemental guidance tailored for a specific technology, environment, or community of interest. Overlays allow sectors (such as healthcare, financial, or defense) to add community-specific requirements on top of the NIST baseline. Control enhancements add functionality to individual controls, compensating controls substitute for required controls, and scoping considerations justify removing or modifying controls.
Question 6: While selecting controls for a new system, a practitioner finds that a required control (AU-9, Protection of Audit Information) cannot be fully implemented due to a technical limitation in the logging platform. What is the MOST appropriate approach per NIST RMF guidance?
- Document the limitation, implement a compensating control that provides equivalent protection, and obtain AO approval (Correct answer)
- Proceed to authorization without implementing AU-9 since the technical limitation is a valid exemption
- Replace AU-9 with an unrelated control that is easier to implement
- Delay the authorization until AU-9 can be fully implemented regardless of schedule impacts
Correct answer: Document the limitation, implement a compensating control that provides equivalent protection, and obtain AO approval
When a required control cannot be implemented as specified, NIST RMF guidance allows for compensating controls — alternative measures that provide equivalent or comparable protection. The compensating control must be documented with a justification, and the authorizing official (AO) must review and accept the residual risk. Simply skipping the control, substituting unrelated controls, or delaying indefinitely are not appropriate RMF responses.
An organization is implementing controls for a newly classified moderate-impact system.
The security engineer notes that NIST SP 800-53 provides a baseline, but some controls seem unnecessary given the system's unique operating environment.
What is the MOST appropriate next step?