nerdexam
(ISC)2

CGRC · Question #269

What is the purpose for scoping guidance? Response:

The correct answer is A. To establish which controls will not be part of the baseline. Scoping guidance is used to identify and remove controls from the security control baseline that are not applicable to a specific information system or organization, ensuring that the baseline remains relevant and efficient. This process helps streamline security efforts by…

Scope of the System

Question

What is the purpose for scoping guidance? Response:

Options

  • ATo establish which controls will not be part of the baseline
  • BTo establish the organizationally defined security parameters
  • CTo establish the high water mark as part of FIPS 199 analysis
  • DTo allow senior management to establish and express their guidance on tailoring the security

How the community answered

(37 responses)
  • A
    89% (33)
  • B
    3% (1)
  • C
    5% (2)
  • D
    3% (1)

Why each option

Scoping guidance is used to identify and remove controls from the security control baseline that are not applicable to a specific information system or organization, ensuring that the baseline remains relevant and efficient. This process helps streamline security efforts by focusing on essential controls.

ATo establish which controls will not be part of the baselineCorrect

Scoping guidance helps an organization determine which security controls within a baseline are not applicable to a specific system or environment and can therefore be excluded. This process ensures that only relevant controls are implemented, avoiding unnecessary effort and cost.

BTo establish the organizationally defined security parameters

Establishing organizationally defined security parameters is part of tailoring and parameter specification within controls, but scoping's primary purpose is to identify what not to include, rather than just defining parameters.

CTo establish the high water mark as part of FIPS 199 analysis

Establishing a "high water mark" as part of FIPS 199 analysis relates to determining the overall security categorization (e.g., high-impact) of a system based on its impact, not the specific purpose of scoping individual controls.

DTo allow senior management to establish and express their guidance on tailoring the security

While senior management's guidance is important for tailoring, the direct purpose of scoping guidance is the technical identification of non-applicable controls for exclusion, which contributes to tailoring but is a more specific action.

Concept tested: Security control tailoring - scoping

Source: https://nvlpubs.nist.gov/nistpubs/specialpublications/nist.sp.800-53r5.pdf

Topics

#Scoping#Security Controls#Control Baseline

Community Discussion

No community discussion yet for this question.

Full CGRC Practice