CGRC · Question #45
Tailoring refers to the process by which a security control baseline is modified based on all but one of the following: Response:
The correct answer is A. The security categorization of the information system. Tailoring is the process of modifying an established security control baseline to align with an organization's specific requirements and operational environment. This modification considers factors such as scoping guidance, compensating controls, and parameter assignments…
Question
Tailoring refers to the process by which a security control baseline is modified based on all but one of the following:
Response:
Options
- AThe security categorization of the information system
- BThe application of scoping guidance
- CThe specification of compensating controls
- DThe specification of organization-defined parameters in controls via explicit assignement and
How the community answered
(50 responses)- A88% (44)
- B2% (1)
- C8% (4)
- D2% (1)
Why each option
Tailoring is the process of modifying an established security control baseline to align with an organization's specific requirements and operational environment. This modification considers factors such as scoping guidance, compensating controls, and parameter assignments within controls.
The security categorization of the information system is used to select the initial security control baseline (e.g., Low, Moderate, High baseline) as per NIST SP 800-53, not as a factor by which that chosen baseline is then modified through the tailoring process itself. Tailoring modifies the chosen baseline based on other factors like scoping, applicability, and compensation, but not the initial categorization.
The application of scoping guidance is a legitimate tailoring activity, where controls are deselected if they are not applicable to the system's scope.
The specification of compensating controls is a valid tailoring method, allowing alternative controls to be used when a primary control cannot be implemented.
The specification of organization-defined parameters in controls is a direct part of tailoring, where generic controls are made specific to an organization's environment.
Concept tested: Security control tailoring factors
Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r5.pdf
Topics
Community Discussion
No community discussion yet for this question.