Which concept includes system-specific, hybrid, and common controls?

Prepare for the Federal IT Security Professional Exam. Study with flashcards and multiple choice questions, each with hints and explanations. Get ready for your certification!

Multiple Choice

Which concept includes system-specific, hybrid, and common controls?

Explanation:
Security control allocation is about deciding how to apply security controls across an information system. It recognizes three ways controls can be implemented: system-specific controls tailored to a particular system’s unique risks, common controls that are inherited across multiple systems within an organization, and hybrid controls that combine elements of both—partly provided as common controls and partly tailored to a specific system. This allocation helps organizations reuse controls to improve efficiency and consistency while still addressing system-specific risk requirements. The other concepts referenced—risk assessment components, which focus on identifying threats, vulnerabilities, and impacts; SP 800-92, which covers security metrics; and the least privilege principle, a design guideline for restricting access—do not describe how controls are distributed or assigned across systems.

Security control allocation is about deciding how to apply security controls across an information system. It recognizes three ways controls can be implemented: system-specific controls tailored to a particular system’s unique risks, common controls that are inherited across multiple systems within an organization, and hybrid controls that combine elements of both—partly provided as common controls and partly tailored to a specific system. This allocation helps organizations reuse controls to improve efficiency and consistency while still addressing system-specific risk requirements.

The other concepts referenced—risk assessment components, which focus on identifying threats, vulnerabilities, and impacts; SP 800-92, which covers security metrics; and the least privilege principle, a design guideline for restricting access—do not describe how controls are distributed or assigned across systems.

Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy