CGRC · Question #428
An information system is currently in the initiation phase of the system development life cycle (SDLC) and has been categorized high impact. The information system owner wants to inherit common…
The correct answer is A. Supplement the common controls with system-specific or hybrid controls to achieve the required. To ensure that common controls inherited from a moderate-impact system adequately protect a high-impact system, the system owner must supplement them with additional system-specific or hybrid controls. This addresses the higher security requirements of the high-impact system.
Question
An information system is currently in the initiation phase of the system development life cycle (SDLC) and has been categorized high impact. The information system owner wants to inherit common controls provided by another organizational information system that is categorized moderate impact. How does the information system owner ensure that the common controls will provide adequate protection for the information system? Response:
Options
- ASupplement the common controls with system-specific or hybrid controls to achieve the required
- BAsk the common control provider for the system security plan for the common controls.
- CConsult with the information system security engineer and the information security architect.
- DPerform rigorous testing of the common controls to determine if they provide adequate protection.
How the community answered
(57 responses)- A74% (42)
- B16% (9)
- C4% (2)
- D7% (4)
Why each option
To ensure that common controls inherited from a moderate-impact system adequately protect a high-impact system, the system owner must supplement them with additional system-specific or hybrid controls. This addresses the higher security requirements of the high-impact system.
When inheriting common controls from a lower-impact system (moderate) to a higher-impact system (high), the inherited controls alone may not meet the more stringent security requirements. The system owner must supplement these common controls with system-specific or hybrid controls to achieve the necessary level of protection for the high-impact categorization.
While obtaining the system security plan is a good practice for understanding the inherited controls, it does not, by itself, ensure adequate protection for a higher-impact system.
Consulting with security professionals is an important advisory step, but it is not the direct action that ensures adequate protection.
Performing rigorous testing verifies the effectiveness of inherited controls but will not inherently increase their strength if they are fundamentally designed for a lower impact.
Concept tested: NIST control inheritance and impact levels
Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r5.pdf
Topics
Community Discussion
No community discussion yet for this question.