CGRC · Domain 7
Compliance Maintenance
About 13% of the exam
The Monitor step
- Monitor system and environment
- Assess controls ongoing
- Respond to findings
- Update SSP, SAR, POA&M
- Report security status
- Ongoing authorization
- Dispose at end of life
- Purpose
- ongoing awareness for timely risk decisions
- Guide
- SP 800-137 for ISCM
- Control
- CA-7 continuous monitoring
- Audience
- AO, risk executive, owners, ISSO
- Outcome
- authorization stays current or is revisited
Continuous means frequent enough for the risk, not instantaneous for everything
ISCM strategy
- Grounded in organizational risk tolerance
- Metrics defined before tools are bought
- Frequencies set per control by risk
- Roles and recipients named per report
- Tied to enterprise architecture
- Reviewed after reorganization or migration
- Assessed with SP 800-137A criteria
ISCM process
- Define
- Establish
- Implement
- Analyze and report
- Respond
- Review and update
- Define strategy from risk tolerance
- Establish metrics, frequencies, architecture
- Implement collection and automation
- Analyze, then report to decision makers
- Respond: mitigate, accept, avoid, share
- Review the program itself
Tiers and roles in monitoring
- Tier 1
- standard metrics, tolerance, program policy
- Tier 2
- mission processes, common controls
- Tier 3
- system-level collection and response
- Risk executive
- sets tolerance the strategy serves
- AO
- only one who can accept new risk
- Common control provider
- monitors, tells every inheritor
- Inheriting owner
- consumes and reassesses impact
Setting frequency
- Volatile controls monitored more often
- High impact raises frequency
- Threat exposure raises frequency
- Stable, low-impact controls less often
- Sampling defensible by homogeneity and risk
- Automation enables higher frequency cheaply
- Frequencies documented in the strategy
Automation standards
- SCAP
- protocol bundling the standards below
- XCCDF
- checklist rules, selection and scoring
- OVAL
- machine-state tests
- CPE
- platform naming
- CVE
- vulnerability identifiers
- CVSS
- severity scoring
- CCE
- configuration identifiers
XCCDF says what to check and how to score; OVAL says how to test the machine
CDM program
- Owner
- DHS CISA for federal agencies
- HWAM
- what hardware is on the network
- SWAM
- what software is running
- CSM
- configuration settings management
- VUL
- vulnerability management
- Who is on the network
- identity, credentials, privileges
- Dashboards
- agency summaries feed federal view
- AWARE
- scores defects, worst first
HWAM and SWAM first: you cannot assess what you have not inventoried
Change, impact and triggers
Security impact analysis
- Before the change, not after
- Which controls does it touch
- Does categorization change
- Does the boundary move
- Update SSP and diagrams together
Significant change
- New interconnection or external service
- New information type, especially PII
- Major architecture or hosting change
- Change in ownership or mission
- Triggers reassessment, maybe reauthorization
Event-driven review
- Risk exceeds tolerance threshold
- Serious incident reveals failed control
- Provider authorization degrades or expires
- New threat against the platform
- AO informed, supported by risk executive
Security status reporting
- Executives: aggregated risk and trends
- Operations: detailed, actionable technical data
- Recipients matched to decision authority
- Cadence set in the strategy
- Metrics comparable across units
- Plain language for non-technical officials
- Reports drive decisions, not shelves
POA&M and metrics in maintenance
- New findings open new items
- Close only with verified evidence
- Disabled, unreachable service: document compensating context
- Failed control from incident: record, update risk
- Mean time to remediate critical vulnerabilities
- Effectiveness metrics beat activity counts
- Unreviewed metrics are a program gap
Decommissioning
- Formal disposal plan approved
- Media sanitized per SP 800-88
- Records retained per schedule
- Inheriting systems notified of lost controls
- Interconnections terminated, ISAs closed
- Inventory and registration updated
- Authorization formally terminated
Monitoring pitfalls
- Scans run nightly, nobody reads results
- Same frequency for every control
- Metrics defined after tools were bought
- Findings stop at the administrator
- Alerts flood, analysts drown
- Provider deliverables ignored
- POA&M closed on promise, not proof
- SSP untouched for years
Rapid recall
- ISCM guide
- SP 800-137
- ISCM program assessment
- SP 800-137A, satisfied or other than
- Monitoring control
- CA-7 continuous monitoring
- Sanitization
- SP 800-88
- Federal tooling
- CDM dashboards, AWARE
- Checklists
- XCCDF inside SCAP
- Risk exceeds tolerance
- inform the AO
- Ongoing authorization prerequisite
- effective ISCM
Reference strip: strategy, automation, change, reporting
Strategy
- Define, establish, implement
- Analyze and report, respond, review
- Frequency by volatility and impact
Automation
- SCAP: XCCDF, OVAL, CPE, CVE, CVSS
- CDM: HWAM, SWAM, CSM, VUL
- Dashboards agency to federal
Change
- Security impact analysis first
- Significant change triggers review
- Update SSP, SAR, POA&M
Reporting
- Tailored to audience
- Reaches the AO
- Standard metrics across units
End of life
- SP 800-88 sanitization
- Records retained, inheritors told
- Authorization formally terminated
Quick exam traps
- Trap: Continuous monitoring means every control is checked in real time
- Trap: Nightly automated scans make human analysis unnecessary
- Trap: Monitoring results can stop at the system administrator
- Trap: OVAL defines the checklist rules and scoring
- Trap: Vulnerability management should mature before asset inventory
- Trap: A POA&M item closes when remediation is scheduled
- Trap: All controls should be monitored at the same frequency
- Trap: Benchmark compliance proves there is no exploitable path
cybercertprep.com · original revision sheet written from the public body of knowledge