nerdexam
(ISC)2

CGRC · Question #431

Overlays can be implemented as part of control tailoring. In which step of the assessment and authorization process is control tailoring done? Response:

The correct answer is D. Select step. Control tailoring, including the application of overlays, is performed during the "Select" step of the NIST Risk Management Framework (RMF) assessment and authorization process. This step involves selecting and tailoring the security controls based on the system's…

Selection and Approval of Framework, Security, and Privacy Controls

Question

Overlays can be implemented as part of control tailoring. In which step of the assessment and authorization process is control tailoring done? Response:

Options

  • APrivacy Impact Assessment (PIA) Step
  • BSecurity Categorization
  • CRisk Assessment
  • DSelect step

How the community answered

(52 responses)
  • A
    2% (1)
  • B
    2% (1)
  • C
    6% (3)
  • D
    90% (47)

Why each option

Control tailoring, including the application of overlays, is performed during the "Select" step of the NIST Risk Management Framework (RMF) assessment and authorization process. This step involves selecting and tailoring the security controls based on the system's categorization and organizational policies.

APrivacy Impact Assessment (PIA) Step

A Privacy Impact Assessment (PIA) focuses on privacy risks and is typically conducted as part of the overall system development lifecycle, but it is not the specific step where security control tailoring occurs.

BSecurity Categorization

Security Categorization is the process of assigning impact levels (low, moderate, high) to information systems based on the potential impact of a loss of confidentiality, integrity, or availability, preceding control selection and tailoring.

CRisk Assessment

Risk Assessment is an ongoing process of identifying, analyzing, and evaluating risks, which informs control selection but is not the step where controls are formally tailored and documented.

DSelect stepCorrect

The "Select" step in the NIST RMF is where an organization selects, tailors, and supplements the baseline security controls based on the system's security categorization, common controls, and applicable overlays, as described in NIST SP 800-37. This ensures the controls are appropriate for the system's specific environment and risk posture.

Concept tested: NIST RMF control tailoring process step

Source: https://csrc.nist.gov/publications/detail/sp/800-37/rev-2/final

Topics

#Control tailoring#Overlays#RMF Select step#Assessment and Authorization process

Community Discussion

No community discussion yet for this question.

Full CGRC Practice