โ† All CAP Flashcard Decks

Security Control Implementation Flashcards

7 cards from real CAP practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Security Control Implementation flashcards as text
  1. What document serves as the primary guide for implementing security controls in an information system?

    Answer: System Security Plan (SSP)

    The System Security Plan documents how security controls are planned and implemented, serving as the authoritative reference for control implementation.

  2. Which NIST publication provides the comprehensive catalog of security and privacy controls for federal information systems?

    Answer: NIST SP 800-53

    NIST SP 800-53 provides the catalog of security and privacy controls that organizations select from when building their control baseline.

  3. What type of security control is implemented centrally by an organization and inherited by multiple information systems?

    Answer: Common control

    Common controls are security controls whose implementation results in a capability that is inherited by one or more organizational information systems.

  4. When a required security control cannot be implemented as specified in the baseline, what alternative mechanism may be used with appropriate documentation?

    Answer: Compensating control

    Compensating controls are alternative management, operational, or technical safeguards employed when standard control implementation is not feasible.

  5. In the NIST Risk Management Framework, which step directly follows the selection of security controls?

    Answer: Implement security controls

    The NIST RMF Step 4 (Implement) follows Step 3 (Select), requiring organizations to implement the selected controls before they can be assessed.

  6. What term describes a security control where implementation is split between the information system owner and a common control provider?

    Answer: Hybrid control

    Hybrid controls have their implementation responsibilities divided between the information system owner and a common control provider.

  7. Which process ensures that security controls remain correctly configured as a system evolves and changes are introduced?

    Answer: Configuration management

    Configuration management controls changes to system components and ensures that security controls remain properly implemented as the system evolves.