CAS-002 · Question #351
A security engineer is a new member to a configuration board at the request of management. The company has two new major IT projects starting this year and wants to plan security into the…
The correct answer is A. Establish the security control baseline to be assessed E. Categorize the applications according to use. The NIST Risk Management Framework requires categorization and security control baseline selection before assessment can occur; skipping these steps invalidates the assessment process.
Question
A security engineer is a new member to a configuration board at the request of management. The company has two new major IT projects starting this year and wants to plan security into the application deployment. The board is primarily concerned with the applications' compliance with federal assessment and authorization standards. The security engineer asks for a timeline to determine when a security assessment of both applications should occur and does not attend subsequent configuration board meetings. If the security engineer is only going to perform a security assessment, which of the following steps in system authorization has the security engineer omitted? (Select TWO).
Options
- AEstablish the security control baseline to be assessed
- BBuild the application according to software development security standards
- CWrite the systems functionality requirements into the security requirements traceability
- DReview the results of user acceptance testing
- ECategorize the applications according to use
- FConsult with the stakeholders to determine which standards can be omitted
How the community answered
(34 responses)- A47% (16)
- B26% (9)
- C9% (3)
- D3% (1)
- F15% (5)
Why each option
The NIST Risk Management Framework requires categorization and security control baseline selection before assessment can occur; skipping these steps invalidates the assessment process.
Establishing the security control baseline (the Select step in the RMF) defines exactly which controls will be assessed; without this, the engineer has no defined scope for the assessment.
Building the application to development standards is an implementation activity outside the security engineer's assessment role and is not a prerequisite step in the RMF authorization process.
Writing security requirements into a traceability matrix is a development or requirements-phase artifact, not a formal RMF step that the assessor is responsible for.
User acceptance testing review is a QA/development activity and is not a defined step in the NIST RMF system authorization process.
Categorizing the system according to impact levels (Confidentiality, Integrity, Availability) is the first RMF step and drives all subsequent control selection and assessment rigor; omitting it means the assessment lacks a defined risk context.
Consulting stakeholders to omit standards is not a recognized RMF step and would be contrary to the federal compliance mandate described in the scenario.
Concept tested: NIST RMF categorize and select steps for system authorization
Source: https://csrc.nist.gov/projects/risk-management/about-rmf
Topics
Community Discussion
No community discussion yet for this question.