CGRC · Domain 5
Assessment and Audit of Security and Privacy Controls
About 16% of the exam
The Assess step
- Select assessor
- Develop the SAP
- Assess controls
- Write the SAR
- Remediate
- Update POA&M
- Assessor
- independent, qualified, chosen early
- SAP
- scope, methods, objects, depth, coverage
- Evidence
- examine, interview, test results
- SAR
- findings, satisfied or other than satisfied
- Initial remediation
- fix quick items before the package
- POA&M
- what remains, by when, by whom
Assess effectiveness, not paperwork: a control that exists but can be bypassed is Other Than Satisfied
Assessor independence
- Free from conflict with the system
- Not the AO, not the implementer
- Higher impact, greater independence
- Objectivity is the point of the SAR
- Reports facts, AO decides risk
- Qualified in the technology assessed
- Common control provider assesses its own scope
Security assessment plan
- Controls in scope and boundary confirmed
- Procedures from SP 800-53A
- Methods and objects per control
- Depth and coverage chosen by impact
- Sampling approach and sizes
- Schedule, roles, rules of engagement
- Approved by AO before fieldwork
- Prior results reused where still valid
SP 800-53A vocabulary
Methods
- Examine
- review, inspect, observe, study
- Interview
- discuss with individuals or groups
- Test
- exercise the mechanism, compare results
Objects
- Specifications
- policies, plans, designs, procedures
- Mechanisms
- hardware, software, firmware safeguards
- Activities
- operations people perform
- Individuals
- people who apply the control
Rigor
- Depth
- basic, focused, comprehensive detail
- Coverage
- how many objects, how representative
- Objective
- from the control's determination statements
- Determination
- satisfied or other than satisfied
A firewall is a mechanism; its rulebase document is a specification; the admin you interview is an individual
Recording findings
- Satisfied: every determination statement met
- Other Than Satisfied: any statement missed
- Explain how it fell short
- Evidence referenced for each finding
- Risk rating supports prioritization
- Recommend, do not decide, remediation
- Design flaw counts even if configured correctly
Security assessment report
- Boundary assessed, matches the SSP
- Methods applied and evidence gathered
- Finding per control with determination
- Severity and recommended corrective action
- Assessor identity and independence statement
- Feeds the POA&M and the AO
- Fixed findings noted with new results
Assessment versus audit
- Assessment
- effectiveness against SSP, RMF activity
- Audit
- conformance to criteria, formal opinion
- Internal audit
- third line, reports to board
- External audit
- independent body, certification or attestation
- FISMA audit
- inspector general annual review
- Self-assessment
- lowest independence, cheapest
- Continuous
- automated, frequent, feeds ISCM
Testing techniques
- Vulnerability scanning, authenticated preferred
- Configuration checks with SCAP content
- Penetration testing, scoped and authorized
- Code review and static analysis
- Log review for control operation
- Social engineering with approval
- Sampling sized to population and risk
- Retest after remediation to close
Control IDs worth knowing
- AC-2, AC-3
- account management, access enforcement
- AC-5, AC-7
- separation of duties, logon attempts
- AU-6, AU-7, AU-9
- review, reduction, protect audit
- CA-5, CA-7
- POA&M, continuous monitoring
- CM-6, CM-7
- settings, least functionality
- CP-4, CP-6, CP-7
- plan test, alternate storage, site
- IA-4
- identifier management
- PL-2
- system security and privacy plan
- SA-11
- developer testing and evaluation
- SC-2, SC-13
- separate management, cryptographic protection
- SI-4, SI-7
- system monitoring, integrity verification
- AT-3
- role-based training
Remediation and the POA&M
- Weakness, source, severity recorded
- Milestones with scheduled completion dates
- Resources required and point of contact
- Status: open, ongoing, completed, risk accepted
- Closed only with verified evidence
- Realistic dates matter most to the AO
- Feeds the authorization package
Assessment pitfalls
- Compliance rates high, incidents still frequent
- Sampling too small for the population
- Testing only what is easy to test
- Assessor reporting to the system owner
- Boundary in SAR differs from SSP
- Reusing stale results after major change
- Scanner says compliant, attack path remains
- Findings closed without retest
Assessing privacy controls
- Same methods, different expertise
- Legal authority to process verified
- Purpose alignment and minimization checked
- Notices and consent mechanisms examined
- PIA and SORN current and accurate
- SAOP or privacy officer involved
- Privacy findings tracked on the POA&M
Rapid recall: method by object
- Read the policy
- examine a specification
- Watch a backup run
- examine an activity
- Ask the administrator
- interview an individual
- Try the lockout
- test a mechanism
- How many servers
- coverage attribute
- How deeply
- depth attribute
- High-impact system
- comprehensive depth, full coverage
Reference strip: plan, methods, report, follow-up
Plan
- SAP approved before fieldwork
- Scope equals SSP boundary
- Depth and coverage by impact
Methods and objects
- Examine, interview, test
- Specifications, mechanisms, activities, individuals
- Basic, focused, comprehensive
Report
- SAR: findings and determinations
- Satisfied or other than satisfied
- Recommendations, not decisions
Follow-up
- POA&M items with dates and owners
- Retest before closing
- Risk accepted items documented
Documents
- SP 800-53A procedures
- SP 800-115 technical testing
- SP 800-53 catalog
- CA family: CA-2, CA-5, CA-7
Quick exam traps
- Trap: SP 800-53A lists the controls and SP 800-53 explains how to assess them
- Trap: A control implemented as documented is automatically Satisfied
- Trap: The assessor decides whether residual risk is acceptable
- Trap: Depth is about how many systems you sample
- Trap: A firewall appliance is an assessment activity
- Trap: A POA&M item can be closed when the fix is scheduled
- Trap: The system owner may act as the independent assessor to save cost
- Trap: A clean SCAP benchmark result proves no exploitable path exists
cybercertprep.com · original revision sheet written from the public body of knowledge