ISC2 Governance, Risk and Compliance (CGRC) Practice Question
A cloud system owner is scheduling a FedRAMP assessment and the selected third-party assessment organization (3PAO) asks for core documentation so it can draft the Security Assessment Plan. Which artifact must the owner provide to the 3PAO first to let the assessor understand the system's security control implementation and testing scope?
System Security Plan that fully describes the implemented NIST 800-53 controls
Signed Authorization to Operate letter from the authorizing official
The Security Assessment Plan (SAP) is built from information that describes how the system is architected, the categorization, and how each NIST 800-53 control is implemented. That level of detail is found in the System Security Plan (SSP). Supplying the SSP lets the 3PAO map implemented controls to test procedures and determine assessment boundaries. A POA&M lists known weaknesses after an assessment, so it is not yet available. An Authorization to Operate letter is issued only after the assessment is complete. The continuous monitoring strategy, while important, is a separate document that does not give the 3PAO the full control implementation narrative required to develop the SAP.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
ELI5: What is the System Security Plan (SSP)?
Open an interactive chat with Bash
What are NIST 800-53 controls?
Open an interactive chat with Bash
What does the Security Assessment Plan (SAP) include?
Open an interactive chat with Bash
ISC2 Governance, Risk and Compliance (CGRC)
System Compliance
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .