ISC2 Governance, Risk and Compliance (CGRC) Practice Question
A federal agency is defining the initial security control baseline for a new information system categorized as Moderate impact under FIPS 199. Which control appears in the NIST SP 800-53 Rev. 5 Moderate baseline but is not required in the Low baseline, making it an important differentiator between the two?
IR-8 Incident Response Plan Testing
CM-3(3) Configuration Change Control | Automated Change Implementation
NIST SP 800-53B lists SC-13 Cryptographic Protection in both the Moderate and High baselines, but it is absent from the Low baseline. The control requires the organization to implement FIPS-validated cryptographic mechanisms to protect the confidentiality and integrity of information. Because it is not part of the Low set, its presence in the Moderate baseline helps ensure additional protection for systems where a compromise could have a serious adverse effect. The other options are either included in all three baselines (e.g., AC-1) or still omitted from the Moderate baseline (e.g., IR-8) or only appear as enhancements in High impact systems (e.g., CM-3(3)).
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
Why is SC-13 Cryptographic Protection required for Moderate and High impact systems but not Low impact systems?
Open an interactive chat with Bash
What does 'FIPS-validated cryptographic mechanisms' mean?
Open an interactive chat with Bash
Why is access control (AC-1) included in all baselines but SC-13 is not?
Open an interactive chat with Bash
ISC2 Governance, Risk and Compliance (CGRC)
Selection and Approval of Framework, Security, and Privacy Controls
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .