ISC2 Governance, Risk and Compliance (CGRC) Practice Question
A federal agency will operate a new SCADA network for water-treatment pumps. It is categorized MODERATE under FIPS 199, and the SP 800-53 moderate baseline has been selected. To address real-time safety needs and device limitations unique to industrial control technology, which action should the team take when tailoring the controls?
Re-categorize the system as LOW impact and adopt the corresponding baseline because SCADA devices lack strong security features.
Apply the NIST SP 800-53 Industrial Control System (ICS) overlay to the moderate baseline and document the changes in the System Security Plan.
Remove all Access Control controls, asserting that proprietary field protocols adequately isolate SCADA components.
Use the moderate baseline exactly as published and rely on post-deployment operational procedures for ICS concerns.
Predefined overlays in NIST SP 800-53 provide technology-specific tailoring guidance. Because SCADA is an industrial control system, applying the ICS overlay modifies, adds, or removes baseline controls to cover safety, availability, and field-device constraints. Recording these adjustments in the System Security Plan meets federal tailoring requirements. Downgrading impact, using the unmodified baseline, or discarding entire control families would leave key risks unaddressed or violate policy.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is an ICS Overlay in NIST SP 800-53?
Open an interactive chat with Bash
What is the purpose of documenting changes in the System Security Plan (SSP)?
Open an interactive chat with Bash
Why is it risky to downgrade impact ratings or discard control families for SCADA systems?
Open an interactive chat with Bash
ISC2 Governance, Risk and Compliance (CGRC)
Selection and Approval of Framework, Security, and Privacy Controls
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .