nerdexam
(ISC)2

CGRC · Question #110

Overlays can be implemented as part of control tailoring after the completion of what process? Response:

The correct answer is B. Security categorization. Overlays, which provide additional security control requirements for specific technologies or mission needs, are implemented as part of control tailoring after the security categorization process is completed.

Selection and Approval of Framework, Security, and Privacy Controls

Question

Overlays can be implemented as part of control tailoring after the completion of what process? Response:

Options

  • ARisk Assessment
  • BSecurity categorization
  • CPrivacy Impact Assessment (PIA)
  • DContingency Plan (CP)

How the community answered

(38 responses)
  • A
    5% (2)
  • B
    92% (35)
  • D
    3% (1)

Why each option

Overlays, which provide additional security control requirements for specific technologies or mission needs, are implemented as part of control tailoring after the security categorization process is completed.

ARisk Assessment

Risk assessment is an ongoing process, but control selection and tailoring, including overlays, typically follow security categorization to establish the initial baseline.

BSecurity categorizationCorrect

Security categorization (e.g., FIPS 199) determines the impact level (low, moderate, high) of an information system, which then dictates the baseline set of security controls. Overlays are applied after this baseline is established to add specialized controls relevant to specific risk areas, technologies, or missions, tailoring the baseline to the system's unique context.

CPrivacy Impact Assessment (PIA)

A Privacy Impact Assessment (PIA) identifies privacy risks but is not the preceding process for applying overlays during control selection and tailoring.

DContingency Plan (CP)

A Contingency Plan (CP) is developed to ensure system recovery, but its completion does not precede the application of overlays during control tailoring.

Concept tested: Control overlays and security categorization.

Source: https://csrc.nist.gov/publications/detail/sp/800-53b/final

Topics

#RMF#Control Tailoring#Security Categorization#Overlays

Community Discussion

No community discussion yet for this question.

Full CGRC Practice