CGRC CGRC Information Security Controls 5 — Questions and Answers
Question 1: According to NIST SP 800-53 Rev 5, which control enhancement for Least Privilege requires that privileged accounts be used only for administrative tasks and not for general-purpose activities?
- AC-6(1) Authorize Access to Security Functions
- AC-6(2) Non-Privileged Access for Non-Privileged Functions (Correct answer)
- AC-6(5) Privileged Accounts
- AC-6(9) Log Use of Privileged Functions
Correct answer: AC-6(2) Non-Privileged Access for Non-Privileged Functions
AC-6(2) requires that users with privileged accounts use non-privileged accounts for non-privileged functions such as web browsing or email.
Question 2: Which document produced during the RMF process describes a system's security and privacy requirements, the controls selected to satisfy those requirements, and the implementation status of each control?
- Security Assessment Report (SAR)
- System Security Plan (SSP) (Correct answer)
- Privacy Impact Assessment (PIA)
- Authorization Decision Document (ADD)
Correct answer: System Security Plan (SSP)
The System Security Plan (SSP) is the primary document that records selected controls, their implementation details, and planned milestones.
Question 3: An auditor finds that user access rights have not been reviewed in over 18 months despite a policy requiring annual reviews. Which NIST SP 800-53 control is most directly violated?
- AC-2 Account Management (Correct answer)
- IA-4 Identifier Management
- PS-4 Personnel Termination
- AU-6 Audit Review and Reporting
Correct answer: AC-2 Account Management
AC-2 (Account Management) requires periodic review of user accounts and access privileges to ensure they remain appropriate.
Question 4: What is the primary distinction between a vulnerability and a threat in information security risk terminology?
- A vulnerability is external; a threat is internal
- A vulnerability is a weakness that can be exploited; a threat is a potential event that could exploit a weakness (Correct answer)
- A vulnerability refers to people; a threat refers to technology
- A vulnerability has known fixes; a threat does not
Correct answer: A vulnerability is a weakness that can be exploited; a threat is a potential event that could exploit a weakness
In NIST risk terminology, a vulnerability is a flaw or weakness while a threat is an event or actor with the potential to exploit that vulnerability.
Question 5: Which NIST SP 800-53 control family addresses requirements for auditing and accountability, including audit log generation and protection?
- SI — System and Information Integrity
- AU — Audit and Accountability (Correct answer)
- CA — Assessment, Authorization, and Monitoring
- RA — Risk Assessment
Correct answer: AU — Audit and Accountability
The AU (Audit and Accountability) control family covers audit log creation, content, storage, protection, and review.
Question 6: During the RMF Prepare step, an organization establishes an organization-wide risk management strategy. Which document most directly captures this strategy?
- System Security Plan (SSP)
- Risk Management Framework Implementation Roadmap
- Organization-level Risk Framing Document / Risk Management Strategy (Correct answer)
- Plan of Action and Milestones (POA&M)
Correct answer: Organization-level Risk Framing Document / Risk Management Strategy
NIST SP 800-37 Rev 2 calls for an organization-level risk management strategy document that frames how risk decisions are made across the enterprise.
Question 7: A healthcare organization subject to HIPAA is implementing NIST controls. Which approach is recommended for mapping HIPAA Security Rule requirements to NIST SP 800-53 controls?
- Treat HIPAA and NIST as entirely separate frameworks with no overlap
- Use NIST SP 800-66 crosswalk guidance to map HIPAA Security Rule safeguards to NIST controls (Correct answer)
- Apply only HIPAA requirements and ignore NIST controls entirely
- Replace HIPAA requirements with NIST controls wherever they conflict
Correct answer: Use NIST SP 800-66 crosswalk guidance to map HIPAA Security Rule safeguards to NIST controls
NIST SP 800-66 provides explicit crosswalk tables mapping HIPAA Security Rule implementation specifications to corresponding NIST SP 800-53 controls.
According to NIST SP 800-53 Rev 5, which control enhancement for Least Privilege requires that privileged accounts be used only for administrative tasks and not for general-purpose activities?