CGRC · Question #83
When a Information System Owner applies a risk based approach to his selection of specific controls; this adjustment is called __________. The revised/tailored control baseline is documented in the…
The correct answer is A. Tailoring. The process of adjusting a control baseline based on a risk-based approach, documenting the revised controls in the system security plan, is referred to as tailoring.
Question
When a Information System Owner applies a risk based approach to his selection of specific controls; this adjustment is called __________. The revised/tailored control baseline is documented in the system security plan. Response:
Options
- ATailoring
- BFailing
- CScoping
- DPassing
How the community answered
(60 responses)- A88% (53)
- B7% (4)
- C3% (2)
- D2% (1)
Why each option
The process of adjusting a control baseline based on a risk-based approach, documenting the revised controls in the system security plan, is referred to as tailoring.
Tailoring is the process of modifying or adjusting a baseline set of security controls to align with the specific risks, mission, and operational environment of an information system. This involves selecting, deselecting, and supplementing controls to ensure they are appropriate and cost-effective for protecting the system based on a risk assessment.
"Failing" is not a recognized term in the context of adjusting security controls.
Scoping defines the applicability and boundaries of the information system and its components, which occurs before control selection and tailoring, but it is not the act of adjusting the controls themselves.
"Passing" is not a recognized term in the context of adjusting security controls.
Concept tested: NIST Risk Management Framework (RMF) - Tailoring
Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r5.pdf
Topics
Community Discussion
No community discussion yet for this question.