Baseline - correct answer ✔✔See control baseline.
Capability - correct answer ✔✔A combination of mutually reinforcing controls implemented by technical
means, physical means and procedural means. Such controls are typically selected to achieve a common
information security or privacy purpose.
Common Control - correct answer ✔✔A security or privacy control that is inherited by multiple
information systems or programs.
Compensating Controls - correct answer ✔✔The security and privacy controls implemented in lieu of the
controls in the baselines described in NIST Special Publication 800-53 that provide equivalent or
comparable protection for a system or organization.
Continuous Monitoring - correct answer ✔✔Maintaining ongoing awareness to support organizational
risk decisions.
Control - correct answer ✔✔See security control and privacy control.
Control Baseline - correct answer ✔✔The set of controls that are applicable to information or an
information system to meet legal, regulatory or policy requirements, as well as address protection needs
for the purpose of managing risk.
Control Enhancement - correct answer ✔✔Augmentation of a control to build in additional, but related,
functionality to the control, increase the strength of the control or add assurance to the control.
Environment of Operation - correct answer ✔✔The physical surroundings in which an information
system processes, stores and transmits information.