Set up baseline controls
Use the baseline controls to inherit a control, mark a control as common, or create a hybrid control. Create a hybrid control to inherit requirements partially from common controls and the remaining requirements are created for the control that was generated from the baseline control.
Before you begin
Role required: sn_irm_cont_auth.system_owner, sn_irm_cont_auth.info_system_sec_officer, sn_irm_cont_auth.info_system_sec_manager
About this task
Hybrid controls not only give you the ability to inherit partial requirements from common controls but also gives you the flexibility to make the best use of the common control requirements while self-implementing the remaining requirements for that control.
In CAM there are two ways to inherit controls from the control objectives sourced from NIST 800-53-r5:
- Inherit from provider
- The control is inherited directly and completely. For example, if the common provider, Building A, provides a control objective that is fire prevention, and this control objective has about three different requirements, namely
fire alarm, smoke detection, and sprinkling, then the control is directly inherited by identifying it as common control.Note:A control associated with one authorization package can be a common provider to another authorization package if the control is marked as a Common control provider in its Authorization package, and that particular package must be in Monitor state. Only then it’s called as a common control.
- Hybrid inheritance
- The control is partially inherited. Only one or a few of the control's requirements are inherited in this case. Considering the preceding example, hybrid inheritance is enabled in the following combinations:
- One of the requirement such as fire alarm can be inherited from Building A, and the other two requirements can be self-implemented.
- One of the requirements such as fire alarm can be inherited from Building A, and another requirement such as smoke detection can be inherited from Building B. The rest of which can be self-implemented.
- All requirements are inherited. This inheritance is not a partial inheritance because at least one of the requirements must be inherited and one must be self-implemented. Therefore this inheritance can’t be termed as hybrid inheritance.
Note:
The role and responsibility of the authorization package must be assigned to an Authorization official (AO) who must review and approve the authorization package when it moves from one state to another. The Information System
Security Officer (ISSO) is required to mark a common control, create a hybrid control, or to identify a control as not applicable as these control objectives are sourced by NIST. After the Authorization official (AO) provides the
approval, the authorization package moves to the Implement state.