CGRC Risk Management Framework 4 — Questions and Answers
Question 1: Which type of security control assessment method involves reviewing policy documents and system configuration files to verify control implementation?
- Test
- Interview
- Examine (Correct answer)
- Observe
Correct answer: Examine
The Examine method involves reviewing documentation, specifications, and records to assess whether controls are in place as described.
Question 2: A federal agency's information system processes personally identifiable information (PII). Which RMF consideration becomes especially important during the Categorize step?
- Availability impact must always be rated High
- Privacy impact must be assessed alongside security categorization (Correct answer)
- PII systems are automatically classified as national security systems
- PII eliminates the need for a Moderate baseline
Correct answer: Privacy impact must be assessed alongside security categorization
NIST SP 800-37 Rev. 2 integrated privacy into the RMF, requiring privacy impact assessment alongside security categorization for systems processing PII.
Question 3: What is the significance of a 'common control' in the RMF context?
- A control that every system must implement regardless of impact level
- A control whose implementation is inherited by multiple information systems (Correct answer)
- A control applied uniformly without any tailoring
- A control tested by the Inspector General annually
Correct answer: A control whose implementation is inherited by multiple information systems
Common controls are security controls whose implementation is managed centrally and inherited by multiple systems, reducing redundant implementation efforts.
Question 4: During which phase of the RMF does the Security Control Assessor (SCA) determine whether controls are implemented correctly and operating as intended?
- Select
- Implement
- Assess (Correct answer)
- Authorize
Correct answer: Assess
The Assess step involves independent assessment of security controls by the SCA to determine their effectiveness before the authorization decision.
Question 5: When an Authorizing Official issues a 'denial of authorization to operate,' what is the immediate required action?
- The system must be decommissioned immediately
- The system must cease operations or implement mitigations to reduce risk to acceptable levels (Correct answer)
- The system may continue operating under enhanced monitoring for 90 days
- The CISO assumes personal liability for the risk
Correct answer: The system must cease operations or implement mitigations to reduce risk to acceptable levels
A denial of ATO means the system cannot operate as-is; either operations must stop or sufficient mitigations must be applied to bring risk to an acceptable level.
Question 6: What is the primary purpose of security control 'overlays' in NIST SP 800-53?
- To replace the standard control catalog for classified systems
- To provide community-specific tailoring guidance for specialized environments or technologies (Correct answer)
- To document exceptions approved by the Authorizing Official
- To add mandatory controls not found in standard baselines
Correct answer: To provide community-specific tailoring guidance for specialized environments or technologies
Overlays provide tailored guidance for specific communities of interest (e.g., healthcare, industrial control systems) to supplement standard control baselines.
Question 7: Which factor primarily determines whether a security control from the NIST SP 800-53 Moderate baseline must be implemented on a system?
- The system's annual operating budget
- The system's FIPS 199 security categorization (Correct answer)
- The organization's risk tolerance statement
- The number of users accessing the system
Correct answer: The system's FIPS 199 security categorization
The FIPS 199 security categorization (Low, Moderate, or High) determines which control baseline applies, guiding which controls must be implemented.
Which type of security control assessment method involves reviewing policy documents and system configuration files to verify control implementation?