ISC2 Governance, Risk and Compliance (CGRC) Practice Question
A municipal water utility is selecting NIST SP 800-53 moderate-impact controls for a new SCADA system but realizes extra safety and availability requirements apply to industrial control environments. Per NIST, how should the team address these needs without altering the system's impact level?
Replace the moderate baseline entirely with the high-impact baseline but note that the impact level remains moderate.
Apply the industrial control system overlay to the moderate baseline and document the tailoring in the SSP.
Re-categorize the system as high-impact so the high baseline automatically covers any additional needs.
Keep the moderate baseline unchanged and record the unique ICS risks as accepted in the risk register.
NIST defines an overlay as a set of security-control specifications that tailors a baseline to unique technology, environmental, or mission needs-including industrial control systems-by adding, refining, or removing controls. Applying the ICS overlay (documented in NIST's industrial control system overlay publications) augments the moderate baseline with safety and operational-technology protections while leaving the original impact categorization intact. Re-categorizing to high impact or swapping in the high baseline would change the impact level or introduce unnecessary controls, and simply accepting the risks would ignore NIST's requirement to tailor baselines to address known gaps.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is an overlay in the NIST SP 800-53 framework?
Open an interactive chat with Bash
What is a SCADA system, and why do industrial control systems require special considerations?
Open an interactive chat with Bash
Why can't the impact level be changed or the baseline swapped in this scenario?
Open an interactive chat with Bash
What is an overlay in the context of NIST SP 800-53?
Open an interactive chat with Bash
Why is applying an ICS overlay better than re-categorizing the system as high-impact?
Open an interactive chat with Bash
How is the tailoring process documented in the System Security Plan (SSP)?
Open an interactive chat with Bash
ISC2 Governance, Risk and Compliance (CGRC)
Selection and Approval of Framework, Security, and Privacy Controls
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .