What best describes tailoring of controls in the control baseline design?

Study for the RMF Steps, Tasks, and Outcomes Test. Get ready for your exam with flashcards, multiple choice questions, and in-depth explanations. Master each step and outcome with ease!

Multiple Choice

What best describes tailoring of controls in the control baseline design?

Explanation:
Tailoring controls means adjusting the standard set of security controls to fit the specific system’s risk posture, environment, and mission requirements, so the resulting baseline is customized rather than one-size-fits-all. This is why the idea of tailoring to produce tailored control baselines is the best description: the baseline is purposefully modified to match the unique conditions of the system. In practice, this means you might remove controls that aren’t relevant, strengthen or add controls where the environment demands it, or replace some controls with compensating measures. The distinctiveness of each system’s risk and operating context drives the tailored baseline, rather than applying the same controls identically across all systems or relying solely on a standard catalog.

Tailoring controls means adjusting the standard set of security controls to fit the specific system’s risk posture, environment, and mission requirements, so the resulting baseline is customized rather than one-size-fits-all. This is why the idea of tailoring to produce tailored control baselines is the best description: the baseline is purposefully modified to match the unique conditions of the system.

In practice, this means you might remove controls that aren’t relevant, strengthen or add controls where the environment demands it, or replace some controls with compensating measures. The distinctiveness of each system’s risk and operating context drives the tailored baseline, rather than applying the same controls identically across all systems or relying solely on a standard catalog.

Subscribe

Get the latest from Passetra

You can unsubscribe at any time. Read our privacy policy