nerdexam
(ISC)2

CGRC · Question #351

A situation in which an information system or application receives protection from security controls (or portions of security controls) that are developed, implemented, assessed, authorized, and…

The correct answer is A. Security Control Inheritance. This question defines the scenario where an information system or application is protected by security controls managed by entities external to or distinct from the system's own responsible entity.

Selection and Approval of Framework, Security, and Privacy Controls

Question

A situation in which an information system or application receives protection from security controls (or portions of security controls) that are developed, implemented, assessed, authorized, and monitored by entities other than those responsible for the system or application; entities either internal or external to the organization where the system or application resides. Response:

Options

  • ASecurity Control Inheritance
  • BNetwork Security Controls
  • CHybrid Security Controls
  • DSystem-Specific Security Control

How the community answered

(43 responses)
  • A
    95% (41)
  • B
    2% (1)
  • C
    2% (1)

Why each option

This question defines the scenario where an information system or application is protected by security controls managed by entities external to or distinct from the system's own responsible entity.

ASecurity Control InheritanceCorrect

Security Control Inheritance refers to the practice where an information system or application leverages protection from controls that are developed, implemented, assessed, authorized, and monitored by other entities. This allows systems to inherit existing security postures and reduce redundant efforts, especially in shared service environments or cloud computing.

BNetwork Security Controls

Network Security Controls are specific types of technical controls focused on network infrastructure, not a concept describing how controls are managed or shared across entities.

CHybrid Security Controls

Hybrid Security Controls describe a mix of common and system-specific controls, not the concept of receiving protection from other entities.

DSystem-Specific Security Control

System-Specific Security Control refers to controls unique to a particular system, which is the opposite of controls provided by other entities.

Concept tested: Security Control Inheritance

Source: https://csrc.nist.gov/glossary/term/security_control_inheritance

Topics

#Security Control Inheritance#Control Selection#Shared Responsibility#Risk Management Framework

Community Discussion

No community discussion yet for this question.

Full CGRC Practice