nerdexam
CompTIA

CAS-002 · Question #351

A security engineer is a new member to a configuration board at the request of management. The company has two new major IT projects starting this year and wants to plan security into the…

The correct answer is A. Establish the security control baseline to be assessed E. Categorize the applications according to use. The NIST Risk Management Framework requires categorization and security control baseline selection before assessment can occur; skipping these steps invalidates the assessment process.

Enterprise Security

Question

A security engineer is a new member to a configuration board at the request of management. The company has two new major IT projects starting this year and wants to plan security into the application deployment. The board is primarily concerned with the applications' compliance with federal assessment and authorization standards. The security engineer asks for a timeline to determine when a security assessment of both applications should occur and does not attend subsequent configuration board meetings. If the security engineer is only going to perform a security assessment, which of the following steps in system authorization has the security engineer omitted? (Select TWO).

Options

  • AEstablish the security control baseline to be assessed
  • BBuild the application according to software development security standards
  • CWrite the systems functionality requirements into the security requirements traceability
  • DReview the results of user acceptance testing
  • ECategorize the applications according to use
  • FConsult with the stakeholders to determine which standards can be omitted

How the community answered

(34 responses)
  • A
    47% (16)
  • B
    26% (9)
  • C
    9% (3)
  • D
    3% (1)
  • F
    15% (5)

Why each option

The NIST Risk Management Framework requires categorization and security control baseline selection before assessment can occur; skipping these steps invalidates the assessment process.

AEstablish the security control baseline to be assessedCorrect

Establishing the security control baseline (the Select step in the RMF) defines exactly which controls will be assessed; without this, the engineer has no defined scope for the assessment.

BBuild the application according to software development security standards

Building the application to development standards is an implementation activity outside the security engineer's assessment role and is not a prerequisite step in the RMF authorization process.

CWrite the systems functionality requirements into the security requirements traceability

Writing security requirements into a traceability matrix is a development or requirements-phase artifact, not a formal RMF step that the assessor is responsible for.

DReview the results of user acceptance testing

User acceptance testing review is a QA/development activity and is not a defined step in the NIST RMF system authorization process.

ECategorize the applications according to useCorrect

Categorizing the system according to impact levels (Confidentiality, Integrity, Availability) is the first RMF step and drives all subsequent control selection and assessment rigor; omitting it means the assessment lacks a defined risk context.

FConsult with the stakeholders to determine which standards can be omitted

Consulting stakeholders to omit standards is not a recognized RMF step and would be contrary to the federal compliance mandate described in the scenario.

Concept tested: NIST RMF categorize and select steps for system authorization

Source: https://csrc.nist.gov/projects/risk-management/about-rmf

Topics

#NIST RMF#security assessment#control baseline#system categorization

Community Discussion

No community discussion yet for this question.

Full CAS-002 Practice