CGRC · Question #682
A large organization has a documented information security policy that has been reviewed and approved by senior officials and readily available to all organizational staff. This information security…
The correct answer is B. Hybrid. Control AC-1, Access Control Policy and Procedures, is classified as a hybrid control because it is addressed by both an organization-wide policy and system-specific procedures implemented by individual system owners.
Question
A large organization has a documented information security policy that has been reviewed and approved by senior officials and readily available to all organizational staff. This information security policy explicitly addresses each of the control families in NIST SP 800-53. Some system owners also established procedures for the technical class of security controls on certain of their systems. In their respective system security plans, control AC-1 Access Control Policy and Procedures (a technical class security control) must be identified as what type of control? Response:
Options
- AFully inheritable
- BHybrid
- CSystem specific
- DInherited
How the community answered
(22 responses)- A5% (1)
- B82% (18)
- C5% (1)
- D9% (2)
Why each option
Control AC-1, Access Control Policy and Procedures, is classified as a hybrid control because it is addressed by both an organization-wide policy and system-specific procedures implemented by individual system owners.
Fully inheritable controls are entirely provided by an external system or common control provider without any system-specific implementation.
A control is classified as 'hybrid' when it is implemented by both the organization as a common control and by the information system as a system-specific control. In this scenario, the organization has a common security policy addressing AC-1, but individual system owners also establish specific procedures, indicating a shared responsibility and a hybrid implementation model.
System specific controls are implemented solely by the information system and are not provided by common controls.
Inherited controls are provided by an external system or common control provider, meaning the information system fully relies on that external implementation.
Concept tested: NIST SP 800-53 Control Inheritance and Hybrid Controls
Source: https://csrc.nist.gov/publications/detail/sp/800-53/rev5/final
Topics
Community Discussion
No community discussion yet for this question.