nerdexam
(ISC)2

CGRC · Question #682

A large organization has a documented information security policy that has been reviewed and approved by senior officials and readily available to all organizational staff. This information security…

The correct answer is B. Hybrid. Control AC-1, Access Control Policy and Procedures, is classified as a hybrid control because it is addressed by both an organization-wide policy and system-specific procedures implemented by individual system owners.

Selection and Approval of Framework, Security, and Privacy Controls

Question

A large organization has a documented information security policy that has been reviewed and approved by senior officials and readily available to all organizational staff. This information security policy explicitly addresses each of the control families in NIST SP 800-53. Some system owners also established procedures for the technical class of security controls on certain of their systems. In their respective system security plans, control AC-1 Access Control Policy and Procedures (a technical class security control) must be identified as what type of control? Response:

Options

  • AFully inheritable
  • BHybrid
  • CSystem specific
  • DInherited

How the community answered

(22 responses)
  • A
    5% (1)
  • B
    82% (18)
  • C
    5% (1)
  • D
    9% (2)

Why each option

Control AC-1, Access Control Policy and Procedures, is classified as a hybrid control because it is addressed by both an organization-wide policy and system-specific procedures implemented by individual system owners.

AFully inheritable

Fully inheritable controls are entirely provided by an external system or common control provider without any system-specific implementation.

BHybridCorrect

A control is classified as 'hybrid' when it is implemented by both the organization as a common control and by the information system as a system-specific control. In this scenario, the organization has a common security policy addressing AC-1, but individual system owners also establish specific procedures, indicating a shared responsibility and a hybrid implementation model.

CSystem specific

System specific controls are implemented solely by the information system and are not provided by common controls.

DInherited

Inherited controls are provided by an external system or common control provider, meaning the information system fully relies on that external implementation.

Concept tested: NIST SP 800-53 Control Inheritance and Hybrid Controls

Source: https://csrc.nist.gov/publications/detail/sp/800-53/rev5/final

Topics

#NIST SP 800-53#Hybrid Controls#Common Controls#System Security Plan

Community Discussion

No community discussion yet for this question.

Full CGRC Practice