โ† All CAP Flashcard Decks

Security Control Implementation Flashcards

7 cards from real CAP practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Security Control Implementation flashcards as text
  1. What is the primary purpose of applying security engineering principles during security control implementation?

    Answer: To integrate security into systems from the design phase

    Security engineering principles ensure that security requirements and controls are built into systems from the beginning rather than retrofitted after development.

  2. When a system owner inherits a common control from an external provider, what responsibility does the system owner retain?

    Answer: Verifying the inherited control adequately satisfies their system's security requirements

    System owners must verify that inherited controls are appropriately implemented and actually satisfy the security requirements for their specific system.

  3. According to NIST SP 800-53, which control baseline applies to an information system with a FIPS 199 overall impact level of Moderate?

    Answer: Moderate baseline

    NIST SP 800-53 directly maps baseline selection to impact level, so a Moderate-impact system uses the Moderate security control baseline.

  4. What is the purpose of security control overlays in the implementation process?

    Answer: To tailor baseline controls for specific technologies, environments, or communities of interest

    Overlays provide tailoring guidance that customizes security control baselines for specific technologies, deployment environments, or sector-specific requirements.

  5. Which concept BEST describes implementing multiple overlapping layers of security controls to protect information system resources?

    Answer: Defense in depth

    Defense in depth involves layering multiple security controls so that if one control fails, additional controls remain in place to protect the system.

  6. During implementation, who is primarily responsible for ensuring that security controls are correctly configured and operational in the information system?

    Answer: The System Owner

    The System Owner has primary accountability for ensuring security controls are properly implemented and operational in accordance with the System Security Plan.

  7. What is a 'security control baseline' as defined in NIST SP 800-53?

    Answer: The initial set of controls corresponding to a system's impact level before tailoring

    A security control baseline is the starting set of controls mapped to a system's impact level (Low, Moderate, or High), which is then tailored to meet specific organizational needs.