FedRAMP Security Controls Implementation & NIST SP 800-53 2 — Questions and Answers
Question 1: Which NIST SP 800-53 control family is responsible for configuration management requirements?
- CM - Configuration Management (Correct answer)
- SI - System and Information Integrity
- SA - System and Services Acquisition
- MP - Media Protection
Correct answer: CM - Configuration Management
CM (Configuration Management) covers baseline configurations, change control, and configuration monitoring for information systems.
Question 2: What is a 'compensating control' in the context of FedRAMP?
- An additional control added beyond the baseline requirements
- An alternative control implemented when the required control cannot be met (Correct answer)
- A control specifically for compensating contractors
- A financial control for managing cloud service costs
Correct answer: An alternative control implemented when the required control cannot be met
A compensating control provides equivalent protection when implementing the required control is not feasible, requiring documented justification and AO approval.
Question 3: In FedRAMP, what is the purpose of the 'Inherited' control designation in the SSP?
- Controls that are inherited from NIST guidance and require no implementation
- Controls fully implemented by the underlying infrastructure provider that the CSP can inherit (Correct answer)
- Controls passed down from previous ATO holders
- Controls that apply only to legacy systems
Correct answer: Controls fully implemented by the underlying infrastructure provider that the CSP can inherit
Inherited controls are security controls fully implemented by an underlying provider (e.g., IaaS), allowing the CSP to inherit their implementation and documentation.
Question 4: Which control in NIST SP 800-53 specifically requires multi-factor authentication for privileged accounts?
- AC-2: Account Management
- AC-17: Remote Access
- IA-2: Identification and Authentication (Correct answer)
- IA-5: Authenticator Management
Correct answer: IA-2: Identification and Authentication
IA-2 (Identification and Authentication) and its enhancements, particularly IA-2(1), require multi-factor authentication for network access to privileged accounts.
Question 5: What does FIPS 140-2 or 140-3 validation requirement mean for FedRAMP cloud systems?
- All data must be encrypted using validated cryptographic modules (Correct answer)
- All staff must pass a FIPS background investigation
- Systems must use only FIPS-approved operating systems
- Annual FIPS compliance audits are required
Correct answer: All data must be encrypted using validated cryptographic modules
FedRAMP requires that cryptographic modules protecting federal data meet FIPS 140-2 or 140-3 validation, ensuring standardized and tested encryption implementations.
Question 6: Which NIST SP 800-53 control family addresses personnel security, including background investigations?
- AT - Awareness and Training
- PS - Personnel Security (Correct answer)
- PE - Physical and Environmental Protection
- PL - Planning
Correct answer: PS - Personnel Security
PS (Personnel Security) covers screening, termination, transfer, and access agreements to reduce insider threat risks.
Question 7: What is the significance of the 'Shared' responsibility designation for a FedRAMP control?
- Both the CSP and the federal agency share implementation responsibility (Correct answer)
- The control is shared across multiple cloud regions
- Multiple 3PAOs must assess the control jointly
- The control cost is split between CSP and government
Correct answer: Both the CSP and the federal agency share implementation responsibility
A Shared control means both the CSP and the federal agency customer have portions of the control implementation, requiring coordination and documentation from both parties.
Which NIST SP 800-53 control family is responsible for configuration management requirements?