CGRC · Question #33
The set of minimum security controls defined for a low - impact, moderate-impact, or high-impact information system. Response:
The correct answer is A. Security Control Baseline. The question describes the core definition of a Security Control Baseline, which is a standardized set of minimum security controls required for information systems based on their impact level (low, moderate, or high).
Question
The set of minimum security controls defined for a low - impact, moderate-impact, or high-impact information system. Response:
Options
- ASecurity Control Baseline
- BMinimum Security Baselines
- CNone of these
- DRevised Control Baseline
How the community answered
(28 responses)- A86% (24)
- B4% (1)
- C7% (2)
- D4% (1)
Why each option
The question describes the core definition of a Security Control Baseline, which is a standardized set of minimum security controls required for information systems based on their impact level (low, moderate, or high).
A Security Control Baseline is a predefined set of security controls selected from NIST SP 800-53 that are deemed appropriate for information systems at a specific impact level (low, moderate, or high) as part of the NIST Risk Management Framework (RMF). These baselines provide a starting point for implementing security.
While "Minimum Security Baselines" sounds similar, "Security Control Baseline" is the specific and recognized terminology used within NIST publications (like SP 800-53 and SP 800-37) to describe these sets of controls.
This choice is incorrect as "Security Control Baseline" is the correct term.
A "Revised Control Baseline" implies an existing baseline has been modified, which is a subsequent step, not the general definition of the initial set of minimum controls.
Concept tested: NIST Security Control Baseline definition
Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r5.pdf
Topics
Community Discussion
No community discussion yet for this question.