nerdexam
(ISC)2

CGRC · Question #428

An information system is currently in the initiation phase of the system development life cycle (SDLC) and has been categorized high impact. The information system owner wants to inherit common…

The correct answer is A. Supplement the common controls with system-specific or hybrid controls to achieve the required. To ensure that common controls inherited from a moderate-impact system adequately protect a high-impact system, the system owner must supplement them with additional system-specific or hybrid controls. This addresses the higher security requirements of the high-impact system.

Selection and Approval of Framework, Security, and Privacy Controls

Question

An information system is currently in the initiation phase of the system development life cycle (SDLC) and has been categorized high impact. The information system owner wants to inherit common controls provided by another organizational information system that is categorized moderate impact. How does the information system owner ensure that the common controls will provide adequate protection for the information system? Response:

Options

  • ASupplement the common controls with system-specific or hybrid controls to achieve the required
  • BAsk the common control provider for the system security plan for the common controls.
  • CConsult with the information system security engineer and the information security architect.
  • DPerform rigorous testing of the common controls to determine if they provide adequate protection.

How the community answered

(57 responses)
  • A
    74% (42)
  • B
    16% (9)
  • C
    4% (2)
  • D
    7% (4)

Why each option

To ensure that common controls inherited from a moderate-impact system adequately protect a high-impact system, the system owner must supplement them with additional system-specific or hybrid controls. This addresses the higher security requirements of the high-impact system.

ASupplement the common controls with system-specific or hybrid controls to achieve the requiredCorrect

When inheriting common controls from a lower-impact system (moderate) to a higher-impact system (high), the inherited controls alone may not meet the more stringent security requirements. The system owner must supplement these common controls with system-specific or hybrid controls to achieve the necessary level of protection for the high-impact categorization.

BAsk the common control provider for the system security plan for the common controls.

While obtaining the system security plan is a good practice for understanding the inherited controls, it does not, by itself, ensure adequate protection for a higher-impact system.

CConsult with the information system security engineer and the information security architect.

Consulting with security professionals is an important advisory step, but it is not the direct action that ensures adequate protection.

DPerform rigorous testing of the common controls to determine if they provide adequate protection.

Performing rigorous testing verifies the effectiveness of inherited controls but will not inherently increase their strength if they are fundamentally designed for a lower impact.

Concept tested: NIST control inheritance and impact levels

Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r5.pdf

Topics

#Control Inheritance#Impact Level#Security Control Tailoring#System Development Life Cycle

Community Discussion

No community discussion yet for this question.

Full CGRC Practice