CGRC · Domain 1
Security and Privacy Governance, Risk Management and Compliance Program
About 16% of the exam
Governance and accountability
- Governance directs, management executes
- Board and senior leaders keep ultimate accountability
- Delegation moves duties, never accountability
- Program charter grants scope and authority
- Steering committee aligns business and security
- Evaluate, direct, monitor: the governing loop
- Three lines: operate, oversee, independently assure
The CISO runs the program; the head of the agency owns the risk
The RMF spine
- Prepare
- Categorize
- Select
- Implement
- Assess
- Authorize
- Monitor
- Prepare
- organization and system level context, roles
- Categorize
- FIPS 199 impact, SP 800-60 types
- Select
- baseline, tailor, allocate, document
- Implement
- put controls in, update SSP
- Assess
- SAP, evidence, SAR, POA&M
- Authorize
- AO accepts risk, decision document
- Monitor
- ongoing assessment, status, updates
SP 800-37 Rev 2: seven steps, Prepare added so everything downstream has context
Roles you must not confuse
- Authorizing official
- senior official, accepts risk, signs
- AO designated representative
- everything except the decision
- System owner
- procures, operates, owns the SSP
- ISSO
- day-to-day security of one system
- ISSM
- program-level security across systems
- Security control assessor
- independent, produces the SAR
- Common control provider
- runs controls many systems inherit
- SAISO or CISO
- agency security program lead
- SAOP
- agency-wide privacy accountability
- Risk executive
- enterprise-wide, consistent risk view
Policy hierarchy
- Policy
- management intent, high level, mandatory
- Standard
- specific mandatory requirement
- Baseline
- minimum configuration for a class
- Procedure
- step by step, how
- Guideline
- recommended, not mandatory
- Exception
- approved, documented, expires
Thou shalt encrypt is policy; AES-256 with these settings is a standard
Laws and mandates
- FISMA 2002, 2014
- federal security program, NIST standards
- E-Government Act 2002
- parent of FISMA, PIA requirement
- Privacy Act 1974
- systems of records, SORNs
- OMB Circular A-130
- managing information as strategic resource
- FIPS 199
- categorization standard, mandatory
- FIPS 200
- minimum security requirements, mandatory
- OMB memoranda
- binding policy direction to agencies
Frameworks and standards
- NIST CSF 2.0
- Govern plus five functions, tiers
- COBIT 2019
- EDM governance, design factors
- ISO/IEC 27001
- certifiable ISMS, clauses 4 to 10
- ISO/IEC 38500
- IT governance: evaluate, direct, monitor
- NIST SP 800-39
- enterprise risk management, three tiers
- NIST SP 800-30
- risk assessment method
- NIST SP 800-53
- control catalog, Rev 5
CSF speaks to executives in outcomes; RMF executes the controls underneath
Risk vocabulary
- Risk appetite
- broad amount leadership will take
- Risk tolerance
- measurable thresholds that operationalize appetite
- Inherent risk
- before controls
- Residual risk
- after controls, what the AO accepts
- KRI
- forward warning against a threshold
- KPI
- goal attainment, looking back
- Risk aggregation
- small risks combine into large
Enterprise risk management: SP 800-39
Three tiers
- Tier 1
- organization: strategy, appetite, governance
- Tier 2
- mission and business process
- Tier 3
- information system, where RMF runs
- Direction
- guidance flows down, feedback flows up
Four components
- Frame
- assumptions, constraints, tolerance, priorities
- Assess
- threats, vulnerabilities, likelihood, impact
- Respond
- accept, avoid, mitigate, share, transfer
- Monitor
- verify, track change, effectiveness
The risk executive function sits at Tier 1 so a High on one system means High on every system
Risk responses
- Accept
- within tolerance, documented, monitored
- Avoid
- stop or never start the activity
- Mitigate
- add controls, reduce likelihood or impact
- Share or transfer
- insurance, contract, shared service
- Not an option
- ignoring the risk
Transfer moves cost, never accountability; the agency still owns the outcome
Quantitative and qualitative analysis
- Qualitative: descriptive levels, matrices
- Semi-quantitative: levels mapped to ranges
- Quantitative: dollars and probabilities
- Precise numbers can convey false precision
- Safeguard justified when cost is below ALE reduction
- Likelihood and impact both always required
- Same scale enterprise-wide for comparability
SLE = AV x EF; ALE = SLE x ARO; value of a control = ALE before minus ALE after minus cost
Governance controls
- Separation of duties
- no one person completes a critical process
- Dual control
- two people act together
- Least privilege
- only what the job needs
- Job rotation
- detects long-running fraud
- AO and SCA split
- independence of the assessment
- Due care
- prudent person standard
- Negligence
- no reasonable safeguards, harm followed
- MOU and ISA
- interconnection terms and security requirements
Running the compliance program
- Awareness changes attention, training builds skill
- Role-based training for privileged users
- Metrics tied to decisions, not activity
- Report posture to leadership on cadence
- Internal audit gives independent assurance
- Harmonize frameworks into one control set
- Ongoing authorization replaces point-in-time
- Continual improvement through management review
Key formulas
- SLE
- asset value x exposure factor
- ALE
- SLE x annual rate of occurrence
- Control value
- ALE reduction minus control cost
- Residual
- inherent risk minus control effect
- Risk
- likelihood combined with impact
- Worked example
- 250k x 0.8 x 0.25 = 50k
Reference strip: steps, roles, documents, frameworks
RMF steps
- Prepare, Categorize, Select
- Implement, Assess, Authorize, Monitor
- Prepare runs at both levels
Roles
- AO decides, AODR recommends
- System owner, ISSO, ISSM
- SCA independent, CCP inherits
- SAISO, SAOP, risk executive
Mandatory documents
- FIPS 199 categorization
- FIPS 200 minimum requirements
- OMB A-130, OMB memoranda
- FISMA, Privacy Act, E-Gov Act
Guidance documents
- SP 800-37 RMF process
- SP 800-39 enterprise risk
- SP 800-30 risk assessment
- SP 800-53 and 53A controls
Governance frameworks
- NIST CSF 2.0 with Govern
- COBIT 2019 EDM and MEA
- ISO 27001 ISMS
- ISO 38500 IT governance
Quick exam traps
- Trap: The CISO holds ultimate accountability for the agency's security posture
- Trap: The AO designated representative may sign the authorization decision
- Trap: Risk tolerance is the broad statement and appetite is the threshold
- Trap: FIPS publications are optional guidance for federal agencies
- Trap: A KPI gives early warning of approaching risk limits
- Trap: An encryption rule with algorithm and key length belongs in the policy
- Trap: Buying insurance transfers the agency's accountability for the outcome
- Trap: The AO can also serve as the control assessor for the same system
cybercertprep.com · original revision sheet written from the public body of knowledge