SlideShare a Scribd company logo
Understanding the Risk Management Framework & (ISC)2 CAP Module 7: Select Controls
Categorize
Select
Implement
Assess
Authorize
Monitor
Understanding the Risk Management Framework & (ISC)2 CAP Module 7: Select Controls
Categorize
Select
Implement
Assess
Authorize
Monitor
Understanding the Risk Management Framework & (ISC)2 CAP Module 7: Select Controls
Understanding the Risk Management Framework & (ISC)2 CAP Module 7: Select Controls
Understanding the Risk Management Framework & (ISC)2 CAP Module 7: Select Controls
Understanding the Risk Management Framework & (ISC)2 CAP Module 7: Select Controls
Understanding the Risk Management Framework & (ISC)2 CAP Module 7: Select Controls
Understanding the Risk Management Framework & (ISC)2 CAP Module 7: Select Controls
Understanding the Risk Management Framework & (ISC)2 CAP Module 7: Select Controls
 NIST SP 800-53
Understanding the Risk Management Framework & (ISC)2 CAP Module 7: Select Controls
Understanding the Risk Management Framework & (ISC)2 CAP Module 7: Select Controls
Data Type
Data
Description Data Sensitivity
Data Type Confidentiality Integrity Availability
Personal Identity and Authentication Moderate Moderate Moderate
Help Desk Services Low Low Low
Budget & Finance Moderate Moderate Low
Accounting Low Moderate Low
Space Operations Low High High
High Watermark Moderate High High
Overall High Watermark High
Understanding the Risk Management Framework & (ISC)2 CAP Module 7: Select Controls
Understanding the Risk Management Framework & (ISC)2 CAP Module 7: Select Controls
Understanding the Risk Management Framework & (ISC)2 CAP Module 7: Select Controls
Understanding the Risk Management Framework & (ISC)2 CAP Module 7: Select Controls
Understanding the Risk Management Framework & (ISC)2 CAP Module 7: Select Controls
Understanding the Risk Management Framework & (ISC)2 CAP Module 7: Select Controls
Understanding the Risk Management Framework & (ISC)2 CAP Module 7: Select Controls
Understanding the Risk Management Framework & (ISC)2 CAP Module 7: Select Controls
Understanding the Risk Management Framework & (ISC)2 CAP Module 7: Select Controls
Understanding the Risk Management Framework & (ISC)2 CAP Module 7: Select Controls
Understanding the Risk Management Framework & (ISC)2 CAP Module 7: Select Controls
Understanding the Risk Management Framework & (ISC)2 CAP Module 7: Select Controls
Understanding the Risk Management Framework & (ISC)2 CAP Module 7: Select Controls
Understanding the Risk Management Framework & (ISC)2 CAP Module 7: Select Controls
NSTISSI No. 1000
Understanding the Risk Management Framework & (ISC)2 CAP Module 7: Select Controls
Understanding the Risk Management Framework & (ISC)2 CAP Module 7: Select Controls
NIST SP 800-18 Rev 1
Understanding the Risk Management Framework & (ISC)2 CAP Module 7: Select Controls
Understanding the Risk Management Framework & (ISC)2 CAP Module 7: Select Controls
Understanding the Risk Management Framework & (ISC)2 CAP Module 7: Select Controls
Appendix A:
Sample Information System Security Plan Template
NSTISSI No. 1000
Understanding the Risk Management Framework & (ISC)2 CAP Module 7: Select Controls
Plan Initiation
Plan
Development
Plan
Implementation
Plan
Maintenance
Recertification
or Retirement
Understanding the Risk Management Framework & (ISC)2 CAP Module 7: Select Controls
Understanding the Risk Management Framework & (ISC)2 CAP Module 7: Select Controls
Understanding the Risk Management Framework & (ISC)2 CAP Module 7: Select Controls
Understanding the Risk Management Framework & (ISC)2 CAP Module 7: Select Controls
Understanding the Risk Management Framework & (ISC)2 CAP Module 7: Select Controls
System 1
Subsystem A
Subsystem B
Subsystem C
Understanding the Risk Management Framework & (ISC)2 CAP Module 7: Select Controls
Information Criteria Security Impact
Confidentiality Low / Moderate / High
Integrity Low / Moderate / High
Availability Low / Moderate / High
Based on: NIST SP 800-60 and FIPS Pub 199
Understanding the Risk Management Framework & (ISC)2 CAP Module 7: Select Controls
Understanding the Risk Management Framework & (ISC)2 CAP Module 7: Select Controls
Understanding the Risk Management Framework & (ISC)2 CAP Module 7: Select Controls
Understanding the Risk Management Framework & (ISC)2 CAP Module 7: Select Controls
Common
Controls
System-
specific
Controls
Hybrid
Controls
NIST SP 800-37 Rev 1
Understanding the Risk Management Framework & (ISC)2 CAP Module 7: Select Controls
Understanding the Risk Management Framework & (ISC)2 CAP Module 7: Select Controls
Understanding the Risk Management Framework & (ISC)2 CAP Module 7: Select Controls
“Compensating security controls are the management,
operational, or technical controls used by an agency in
lieu of prescribed controls in the low, moderate, or high
security control baselines, which provide equivalent or
comparable protection for an information system.”
Source: NIST SP 800-100 § 8.4.4
1
• Select controls from 800-53
2
• Complete and convincing rationale
3
• Assess and formally accept risk
1
• Agency has developed on documented common controls
2
• Agency has assigned responsibility of the common control
3
• Systems owners should be made aware
4
• Expert in the common control consulted
5
• Agency, Campus or Center Common Control
Understanding the Risk Management Framework & (ISC)2 CAP Module 7: Select Controls
Understanding the Risk Management Framework & (ISC)2 CAP Module 7: Select Controls
Understanding the Risk Management Framework & (ISC)2 CAP Module 7: Select Controls
Source: NIST SP 800-100 § 8.4.1
Criteria Rating
Confidentiality Moderate
Availability Low
Integrity Low
Understanding the Risk Management Framework & (ISC)2 CAP Module 7: Select Controls
Understanding the Risk Management Framework & (ISC)2 CAP Module 7: Select Controls
Understanding the Risk Management Framework & (ISC)2 CAP Module 7: Select Controls

More Related Content

PDF
Understanding the Risk Management Framework & (ISC)2 CAP Module 10: Authorize
PDF
Understanding the Risk Management Framework & (ISC)2 CAP Module 6: Categorize
PDF
Understanding the Risk Management Framework & (ISC)2 CAP Module 3: Roles
PDF
Understanding the Risk Management Framework & (ISC)2 CAP Module 8: Implement ...
PDF
Understanding the Risk Management Framework & (ISC)2 CAP Module 11: Monitor
PDF
Understanding the Risk Management Framework & (ISC)2 CAP Module 9: Assess Con...
PDF
Understanding the Risk Management Framework & (ISC)2 CAP Module 2: Introduction
PPTX
RMF Roles and Responsibilities (Part 1)
Understanding the Risk Management Framework & (ISC)2 CAP Module 10: Authorize
Understanding the Risk Management Framework & (ISC)2 CAP Module 6: Categorize
Understanding the Risk Management Framework & (ISC)2 CAP Module 3: Roles
Understanding the Risk Management Framework & (ISC)2 CAP Module 8: Implement ...
Understanding the Risk Management Framework & (ISC)2 CAP Module 11: Monitor
Understanding the Risk Management Framework & (ISC)2 CAP Module 9: Assess Con...
Understanding the Risk Management Framework & (ISC)2 CAP Module 2: Introduction
RMF Roles and Responsibilities (Part 1)

What's hot (20)

PDF
Understanding the Risk Management Framework & (ISC)2 CAP Module 15: Incident ...
PPTX
Introduction to NIST’s Risk Management Framework (RMF)
PPTX
INFOSECFORCE Risk Management Framework Transition Plan
PDF
Guide for Applying The Risk Management Framework to Federal Information Systems
PDF
Understanding the Risk Management Framework & (ISC)2 CAP Module 4: Life Cycle
PDF
Information Security Continuous Monitoring within a Risk Management Framework
PPTX
Continuous Monitoring: Getting Past Complexity & Reducing Risk
PDF
Understanding the Risk Management Framework & (ISC)2 CAP Module 13: Contingen...
PDF
Understanding the Risk Management Framework & (ISC)2 CAP Module 1: Exam
PPTX
Developing a Continuous Monitoring Action Plan
PPTX
Achieving Continuous Monitoring with Security Automation
PDF
SuprTEK Continuous Monitoring
PDF
NIST cybersecurity framework
PDF
NIST SP 800 30 Flow Chart
PPTX
Stop Chasing the Version: Compliance with CIPv5 through CIPv99
PDF
Magic quadrant for operational risk management solutions
PPTX
Logging, monitoring and auditing
PDF
Understanding the NIST Risk Management Framework: 800-37 Rev. 2
PPT
It Audit Expectations High Detail
PDF
RISK MANAGEMENT: 4 ESSENTIAL FRAMEWORKS
Understanding the Risk Management Framework & (ISC)2 CAP Module 15: Incident ...
Introduction to NIST’s Risk Management Framework (RMF)
INFOSECFORCE Risk Management Framework Transition Plan
Guide for Applying The Risk Management Framework to Federal Information Systems
Understanding the Risk Management Framework & (ISC)2 CAP Module 4: Life Cycle
Information Security Continuous Monitoring within a Risk Management Framework
Continuous Monitoring: Getting Past Complexity & Reducing Risk
Understanding the Risk Management Framework & (ISC)2 CAP Module 13: Contingen...
Understanding the Risk Management Framework & (ISC)2 CAP Module 1: Exam
Developing a Continuous Monitoring Action Plan
Achieving Continuous Monitoring with Security Automation
SuprTEK Continuous Monitoring
NIST cybersecurity framework
NIST SP 800 30 Flow Chart
Stop Chasing the Version: Compliance with CIPv5 through CIPv99
Magic quadrant for operational risk management solutions
Logging, monitoring and auditing
Understanding the NIST Risk Management Framework: 800-37 Rev. 2
It Audit Expectations High Detail
RISK MANAGEMENT: 4 ESSENTIAL FRAMEWORKS
Ad

Similar to Understanding the Risk Management Framework & (ISC)2 CAP Module 7: Select Controls (20)

DOC
It security-plan-template
PPTX
Federal government security planning
DOCX
INSERT AGENCY LOGOINSERT SYSTEM NAMESystem Secur.docx
PDF
NIST Special Publication 800-53 Revision 5
PDF
Implementing ID Governance in Complex Environments-HyTrust & CA Technologies
PDF
1 info sec+risk-mgmt
PDF
White Paper Guide For Developing Security Plans
PDF
20201014 iso27001 iso27701 nist v2 (extended version)
PDF
Rmf step-3-control-selection-nist-sp-800-53r4
DOCX
CSA CCM V3.0.1 CLOUD CONTROLS MATRIX VERSION 3.0.1Control DomainC.docx
DOCX
CSA CCM V3.0CLOUD CONTROLS MATRIX VERSION 3.0Control DomainCCM V3..docx
PPTX
System Security Plans 101
PDF
NIST Policy Mapped to 800-53-800-53A-controls-and-objectives (Legal Size)
PDF
CISSP Prep: Ch 1: Security Governance Through Principles and Policies
PDF
(1b) Map CSC v5.0 to NIST SP 800 53 Revision 4 (security control table landsc...
PDF
1. Security and Risk Management
PDF
Demystifying the Cyber NISTs
PDF
CISSP -Access Control Domain knowlege.pdf
PPTX
Security Policies and Standards
PPTX
Week 1 - Introduction to CyberSecurity.pptx
It security-plan-template
Federal government security planning
INSERT AGENCY LOGOINSERT SYSTEM NAMESystem Secur.docx
NIST Special Publication 800-53 Revision 5
Implementing ID Governance in Complex Environments-HyTrust & CA Technologies
1 info sec+risk-mgmt
White Paper Guide For Developing Security Plans
20201014 iso27001 iso27701 nist v2 (extended version)
Rmf step-3-control-selection-nist-sp-800-53r4
CSA CCM V3.0.1 CLOUD CONTROLS MATRIX VERSION 3.0.1Control DomainC.docx
CSA CCM V3.0CLOUD CONTROLS MATRIX VERSION 3.0Control DomainCCM V3..docx
System Security Plans 101
NIST Policy Mapped to 800-53-800-53A-controls-and-objectives (Legal Size)
CISSP Prep: Ch 1: Security Governance Through Principles and Policies
(1b) Map CSC v5.0 to NIST SP 800 53 Revision 4 (security control table landsc...
1. Security and Risk Management
Demystifying the Cyber NISTs
CISSP -Access Control Domain knowlege.pdf
Security Policies and Standards
Week 1 - Introduction to CyberSecurity.pptx
Ad

More from Donald E. Hester (18)

PDF
Cybersecurity for Local Gov for SAMFOG
PDF
2017 IT Control Environment for Local Gov
PPTX
What you Need To Know About Ransomware
PDF
CNT 54 Administering Windows Client
PDF
2016 Maze Live Fraud Environment
PDF
2016 Maze Live Changes in Grant Management and How to Prepare for the Single ...
PDF
2016 Maze Live Cyber-security for Local Governments
PDF
GASB 68 and 71 Planning for the Second Year
PDF
Implementing GASB 72: Fair Value Measurement and Application
PDF
2016 Maze Live 1 GASB update
PPTX
Cyber Security for Local Gov SAMFOG
PDF
Annual Maze Live Event 2016 – GASB Updates & Best Practices
PDF
Payment Card Cashiering for Local Governments 2016
PDF
Understanding the Risk Management Framework & (ISC)2 CAP Module 14: Security ...
PDF
Understanding the Risk Management Framework & (ISC)2 CAP Module 12: Cloud Com...
PDF
Understanding the Risk Management Framework & (ISC)2 CAP Module 5: Planning
PPTX
RMF Roles and Responsibilities (Part 2)
PPTX
Building and Maintaining a Successful RMF Program
Cybersecurity for Local Gov for SAMFOG
2017 IT Control Environment for Local Gov
What you Need To Know About Ransomware
CNT 54 Administering Windows Client
2016 Maze Live Fraud Environment
2016 Maze Live Changes in Grant Management and How to Prepare for the Single ...
2016 Maze Live Cyber-security for Local Governments
GASB 68 and 71 Planning for the Second Year
Implementing GASB 72: Fair Value Measurement and Application
2016 Maze Live 1 GASB update
Cyber Security for Local Gov SAMFOG
Annual Maze Live Event 2016 – GASB Updates & Best Practices
Payment Card Cashiering for Local Governments 2016
Understanding the Risk Management Framework & (ISC)2 CAP Module 14: Security ...
Understanding the Risk Management Framework & (ISC)2 CAP Module 12: Cloud Com...
Understanding the Risk Management Framework & (ISC)2 CAP Module 5: Planning
RMF Roles and Responsibilities (Part 2)
Building and Maintaining a Successful RMF Program

Recently uploaded (20)

PDF
Abhay Bhutada and Other Visionary Leaders Reinventing Governance in India
PPTX
Proposed Odisha State Highways Authority OSHA Act 2025 Draft
PPTX
怎么办休斯敦大学维多利亚分校毕业证电子版成绩单办理|UHV在读证明信
PDF
2025 Shadow report on Ukraine's progression regarding Chapter 29 of the acquis
PDF
Population Estimates 2025 Regional Snapshot 08.11.25
PPTX
DFARS Part 249 - Termination Of Contracts
PDF
2026 RMHC Terms & Conditions agreement - updated 8.1.25.pdf
PDF
Strategic Planning for Child Rights and Protection Programming.pdf
PDF
Contributi dei parlamentari del PD - Contributi L. 3/2019
PDF
ISO-9001-2015-internal-audit-checklist2-sample.pdf
PPTX
Weekly Report 17-10-2024_cybersecutity.pptx
PPTX
Quiz - Saturday.pptxaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa
PPTX
Social_Medias_Parents_Education_PPT.pptx
PDF
Environmental Management Basics 2025 for BDOs WBCS by Samanjit Sen Gupta.pdf
PDF
सुशासन सप्ताह भारत रत्न श्री अटल बिहारी बाजपेयी जी जन्मदिवस समारोह 19-24 दिसं...
PPTX
STG - Sarikei 2025 Coordination Meeting.pptx
DOCX
Alexistogel: Solusi Tepat untuk Anda yang Cari Bandar Toto Macau Resmi
PDF
buyers sellers meeting of mangoes in mahabubnagar.pdf
PPTX
AMO Pune Complete information and work profile
PPTX
26.1.2025 venugopal K Awarded with commendation certificate.pptx
Abhay Bhutada and Other Visionary Leaders Reinventing Governance in India
Proposed Odisha State Highways Authority OSHA Act 2025 Draft
怎么办休斯敦大学维多利亚分校毕业证电子版成绩单办理|UHV在读证明信
2025 Shadow report on Ukraine's progression regarding Chapter 29 of the acquis
Population Estimates 2025 Regional Snapshot 08.11.25
DFARS Part 249 - Termination Of Contracts
2026 RMHC Terms & Conditions agreement - updated 8.1.25.pdf
Strategic Planning for Child Rights and Protection Programming.pdf
Contributi dei parlamentari del PD - Contributi L. 3/2019
ISO-9001-2015-internal-audit-checklist2-sample.pdf
Weekly Report 17-10-2024_cybersecutity.pptx
Quiz - Saturday.pptxaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa
Social_Medias_Parents_Education_PPT.pptx
Environmental Management Basics 2025 for BDOs WBCS by Samanjit Sen Gupta.pdf
सुशासन सप्ताह भारत रत्न श्री अटल बिहारी बाजपेयी जी जन्मदिवस समारोह 19-24 दिसं...
STG - Sarikei 2025 Coordination Meeting.pptx
Alexistogel: Solusi Tepat untuk Anda yang Cari Bandar Toto Macau Resmi
buyers sellers meeting of mangoes in mahabubnagar.pdf
AMO Pune Complete information and work profile
26.1.2025 venugopal K Awarded with commendation certificate.pptx

Understanding the Risk Management Framework & (ISC)2 CAP Module 7: Select Controls