Skip to content

Technical Question: Parts vs Groups #36

Answered by xee5ch
Credentive-Sec asked this question in Q&A
Discussion options

You must be logged in to vote

First off, sorry no one else jumped to answer. I had to think about this one but I have a practical answer, it might not explain why. In a catalog, you can have:

  • controls
  • groups of controls
  • groups of groups
  • groups of parts, and in the parts controls or other groups

You cannot have top-level parts, you can only have controls at the top-level or groups therein. So you can have a "part of a group [of groups or controls]" or a "part of a control" but not the other way around.

I got this practical explanation from the current model definition and the the current version of the NIST SP 800-53 and 800-53A catalog.

As for why? That's less clear and a good question. I think the answer is in the …

Replies: 2 comments

Comment options

You must be logged in to vote
0 replies
Answer selected by Credentive-Sec
Comment options

You must be logged in to vote
0 replies
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
1 participant