nerdexam
(ISC)2

CGRC · Question #377

Common control providers have the responsibility for development, implementation, assessment, and monitoring of common controls. In which document do common control providers document common controls?

The correct answer is B. System security and privacy plan. Common control providers document the development, implementation, assessment, and monitoring details of their common controls within their System Security and Privacy Plan.

Implementation of Security and Privacy Controls

Question

Common control providers have the responsibility for development, implementation, assessment, and monitoring of common controls. In which document do common control providers document common controls? Response:

Options

  • APlan of Action and Milestones (POA&M)
  • BSystem security and privacy plan
  • CSecurity Assessment Report (SAR)
  • DSecurity Puthorization Plan (SAP)

How the community answered

(39 responses)
  • A
    3% (1)
  • B
    87% (34)
  • C
    8% (3)
  • D
    3% (1)

Why each option

Common control providers document the development, implementation, assessment, and monitoring details of their common controls within their System Security and Privacy Plan.

APlan of Action and Milestones (POA&M)

A Plan of Action and Milestones (POA&M) tracks and reports the remediation of security weaknesses, not the documentation of common controls themselves.

BSystem security and privacy planCorrect

NIST guidance, particularly SP 800-18, specifies that common controls, including their description, implementation details, assessment results, and monitoring strategies, are documented within the System Security and Privacy Plan of the system or organization providing them. This plan serves as a comprehensive record of the security posture.

CSecurity Assessment Report (SAR)

A Security Assessment Report (SAR) documents the findings of an assessment, including vulnerabilities, but it is not the primary document for defining common controls.

DSecurity Puthorization Plan (SAP)

A Security Authorization Plan (SAP) outlines the scope and methodology for a security assessment and authorization, but it does not serve as the primary documentation for common controls.

Concept tested: NIST RMF documentation - Common Controls

Source: https://csrc.nist.gov/publications/detail/sp/800-18/rev-1/final

Topics

#Common Controls#System Security Plan#NIST RMF Documentation#Control Implementation

Community Discussion

No community discussion yet for this question.

Full CGRC Practice