CGRC · Question #431
Overlays can be implemented as part of control tailoring. In which step of the assessment and authorization process is control tailoring done? Response:
The correct answer is D. Select step. Control tailoring, including the application of overlays, is performed during the "Select" step of the NIST Risk Management Framework (RMF) assessment and authorization process. This step involves selecting and tailoring the security controls based on the system's…
Question
Overlays can be implemented as part of control tailoring. In which step of the assessment and authorization process is control tailoring done? Response:
Options
- APrivacy Impact Assessment (PIA) Step
- BSecurity Categorization
- CRisk Assessment
- DSelect step
How the community answered
(52 responses)- A2% (1)
- B2% (1)
- C6% (3)
- D90% (47)
Why each option
Control tailoring, including the application of overlays, is performed during the "Select" step of the NIST Risk Management Framework (RMF) assessment and authorization process. This step involves selecting and tailoring the security controls based on the system's categorization and organizational policies.
A Privacy Impact Assessment (PIA) focuses on privacy risks and is typically conducted as part of the overall system development lifecycle, but it is not the specific step where security control tailoring occurs.
Security Categorization is the process of assigning impact levels (low, moderate, high) to information systems based on the potential impact of a loss of confidentiality, integrity, or availability, preceding control selection and tailoring.
Risk Assessment is an ongoing process of identifying, analyzing, and evaluating risks, which informs control selection but is not the step where controls are formally tailored and documented.
The "Select" step in the NIST RMF is where an organization selects, tailors, and supplements the baseline security controls based on the system's security categorization, common controls, and applicable overlays, as described in NIST SP 800-37. This ensures the controls are appropriate for the system's specific environment and risk posture.
Concept tested: NIST RMF control tailoring process step
Source: https://csrc.nist.gov/publications/detail/sp/800-37/rev-2/final
Topics
Community Discussion
No community discussion yet for this question.