CGRC · Question #422
Which three classifications of security controls have been identified by NIST based on the responsibility for their provision? Response:
The correct answer is A. System-specific, hybrid, and common. NIST categorizes security controls based on provisioning responsibility into system-specific, hybrid, and common controls. This classification helps in determining who is responsible for implementing and managing each control.
Question
Which three classifications of security controls have been identified by NIST based on the responsibility for their provision? Response:
Options
- ASystem-specific, hybrid, and common
- BTechnical, operational, and managerial
- CAC, IA, and MP
- DPreventive, detective, and corrective
How the community answered
(18 responses)- A89% (16)
- B6% (1)
- C6% (1)
Why each option
NIST categorizes security controls based on provisioning responsibility into system-specific, hybrid, and common controls. This classification helps in determining who is responsible for implementing and managing each control.
NIST Special Publication 800-53 identifies common, system-specific, and hybrid controls based on how they are provided and shared across systems. Common controls are inherited, system-specific controls are unique to one system, and hybrid controls combine both aspects.
Technical, operational, and managerial are classifications based on the type of control, not the responsibility for their provision.
AC, IA, and MP are control families (Access Control, Identification and Authentication, Media Protection) within NIST SP 800-53, not classifications by provisioning responsibility.
Preventive, detective, and corrective are classifications based on the function or timing of the control, not the responsibility for their provision.
Concept tested: NIST control responsibility classifications
Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r5.pdf
Topics
Community Discussion
No community discussion yet for this question.