CGRC · Domain 4
Implementation of Security and Privacy Controls
About 17% of the exam
The Implement step
- Implement per the approved SSP
- Apply secure configuration
- Verify inherited controls
- Record as-implemented details
- Update the SSP
- Input
- approved SSP with allocations and parameters
- Method
- engineering practices within the SDLC
- Change
- deviations go back through approval
- Evidence
- configurations, screenshots, procedures, tickets
- Output
- SSP describing controls as they exist
The SSP leaves Implement describing reality, not intent; the assessor tests what is written
Quality implementation statements
- Who is responsible, by role
- What mechanism or procedure does it
- How it is configured, with parameters
- Which data or components it covers
- Where evidence can be found
- The system uses encryption is inadequate
- Inherited portion and system portion both stated
Implementation status
- Implemented
- in place, operating as described
- Partially implemented
- gaps tracked on the POA&M
- Planned
- not yet in place, dated
- Alternative implementation
- compensating, equivalent protection
- Not applicable
- justified, traceable to tailoring
- Inherited
- provider named, scope stated
Marking planned as implemented makes the AO accept risk that was never disclosed
C-SCRM foundations
- SP 800-161 Rev 1 is the guide
- Cross-disciplinary team, not security alone
- Three tiers: enterprise, mission, operational
- Enterprise sets supply chain risk appetite
- Criticality analysis ranks what matters
- Assess suppliers continuously, not once
- Requirements defined at acquisition planning
- Supports and expands the SR family
SR control family
- SR-1
- policy and procedures
- SR-2
- supply chain risk management plan
- SR-3
- supply chain controls and processes
- SR-4
- provenance, pedigree, chain of custody
- SR-5
- acquisition strategies, tools, methods
- SR-6
- supplier assessments and reviews
- SR-8
- notification agreements
- SR-10
- inspection of systems or components
- SR-11
- component authenticity, anti-counterfeit
- SR-12
- component disposal
Supply chain threats
- Compromised update channel
- trojanized signed release, one node many victims
- Source compromise
- stolen maintainer credentials, backdoor commit
- Malicious hardware insertion
- altered chip at untrusted foundry
- Counterfeit components
- too cheap, no channel paperwork
- Dependency confusion
- public package shadows private name
- Single-source failure
- one foundry, one disaster
- Ownership change
- supplier acquired by adversary
Software supply chain assurance
- SBOM
- component inventory, SPDX or CycloneDX
- SLSA provenance
- attests the build pipeline
- in-toto
- attests each pipeline step
- Code signing
- authenticity and post-build tamper detection
- Pinning
- known-good versions with hashes
- Secure development attestation
- OMB M-22-18, CISA repository
- SAE AS6171
- counterfeit part test methods
SBOM tells you where the vulnerable component is; criticality analysis tells you which system to fix first
Acquisition and contracts
Flow-down and law
- SP 800-171 for CUI at contractors
- FAR and DFARS security clauses
- Section 889: no covered telecom equipment
- FASC coordinates federal acquisition security
- Privacy Act clauses bind contractors
Contract terms
- Breach and compromise notification triggers
- Right to audit and assess
- Secure development attestation and artifacts
- Survival, data return and destruction
- Change of ownership notice
Buying tactics
- Authorized channels only
- Diverse sources, blind purchases
- Independent authentication of suspect parts
- Second source for critical items
- Self-attestation without artifacts weighs little
Verifying inherited controls
- Confirm the provider authorization is current
- Read the provider's scope and conditions
- Check adequacy for your impact level
- Document what the provider leaves to you
- Expiring provider authorization weakens your basis
- Provider assessment failures flow downstream
- Consume the provider's monitoring outputs
Secure configuration
- CM-6 configuration settings from checklists
- CM-7 least functionality, disable the rest
- STIGs and CIS benchmarks as sources
- Baseline recorded, deviations approved
- SCAP content checks compliance automatically
- Golden images for repeatable builds
- Configuration drift is a finding
Implementing privacy controls
- Collect only what the purpose needs
- Retention schedules enforced technically
- Consent mechanisms where required
- Privacy notices at collection points
- De-identification per SP 800-188
- Access to PII logged and reviewed
- Breach response plan per OMB M-17-12
- Contractors bound by Privacy Act terms
Change during implementation
- Security impact analysis before any change
- Deviations from SSP go back for approval
- Configuration control board records decisions
- Update diagrams and inventory together
- Test in non-production first
- Version the SSP with each update
- Build the evidence trail as you go
Rapid recall: supply chain
- Guide
- SP 800-161 Rev 1
- Control family
- SR, new in Rev 5
- Provenance
- SR-4, pedigree at SR-4(4)
- Notification agreements
- SR-8, supplier tells you
- Inspection
- SR-10, random or on delivery
- Contractor CUI
- SP 800-171
- Covered telecom
- Section 889 Parts A and B
- SBOM standard
- SPDX, ISO/IEC 5962
Reference strip: statements, status, supply chain, configuration
Implementation statements
- Role, mechanism, configuration, scope
- Evidence location named
- Inherited and system parts split
Status words
- Implemented, partially, planned
- Alternative, not applicable, inherited
- Partial and planned feed the POA&M
C-SCRM
- SP 800-161, SR family
- Criticality analysis, supplier assessment
- Cross-functional team, three tiers
Software assurance
- SBOM, SLSA, in-toto
- Signing, pinning, private registries
- Attestation via CISA repository
Configuration
- CM-6 settings, CM-7 least functionality
- STIG, CIS, SCAP
- Baseline, drift, change control
Quick exam traps
- Trap: The SSP is frozen once implementation starts
- Trap: A control marked planned may be listed as implemented if funded
- Trap: Supplier risk assessed at onboarding needs no repeat
- Trap: Supply chain risk decisions belong to the security team alone
- Trap: A vendor's self-attestation carries the same weight as an audit
- Trap: An SBOM tells you which systems to remediate first
- Trap: SP 800-171 applies to federal agency systems
- Trap: Benchmark compliance means the system is secure
cybercertprep.com · original revision sheet written from the public body of knowledge