CGRC · Question #269
What is the purpose for scoping guidance? Response:
The correct answer is A. To establish which controls will not be part of the baseline. Scoping guidance is used to identify and remove controls from the security control baseline that are not applicable to a specific information system or organization, ensuring that the baseline remains relevant and efficient. This process helps streamline security efforts by…
Question
What is the purpose for scoping guidance? Response:
Options
- ATo establish which controls will not be part of the baseline
- BTo establish the organizationally defined security parameters
- CTo establish the high water mark as part of FIPS 199 analysis
- DTo allow senior management to establish and express their guidance on tailoring the security
How the community answered
(37 responses)- A89% (33)
- B3% (1)
- C5% (2)
- D3% (1)
Why each option
Scoping guidance is used to identify and remove controls from the security control baseline that are not applicable to a specific information system or organization, ensuring that the baseline remains relevant and efficient. This process helps streamline security efforts by focusing on essential controls.
Scoping guidance helps an organization determine which security controls within a baseline are not applicable to a specific system or environment and can therefore be excluded. This process ensures that only relevant controls are implemented, avoiding unnecessary effort and cost.
Establishing organizationally defined security parameters is part of tailoring and parameter specification within controls, but scoping's primary purpose is to identify what not to include, rather than just defining parameters.
Establishing a "high water mark" as part of FIPS 199 analysis relates to determining the overall security categorization (e.g., high-impact) of a system based on its impact, not the specific purpose of scoping individual controls.
While senior management's guidance is important for tailoring, the direct purpose of scoping guidance is the technical identification of non-applicable controls for exclusion, which contributes to tailoring but is a more specific action.
Concept tested: Security control tailoring - scoping
Source: https://nvlpubs.nist.gov/nistpubs/specialpublications/nist.sp.800-53r5.pdf
Topics
Community Discussion
No community discussion yet for this question.