ISC2 Governance, Risk and Compliance (CGRC) Practice Question
A U.S. federal agency plans to migrate its on-premises human-resources database, which stores Social Security numbers and home addresses, to a FedRAMP-authorized SaaS provider. Before any PII is transferred, which action is specifically required by OMB privacy guidance?
Apply Controlled Unclassified Information markings and implement NIST SP 800-171 controls
Validate the SaaS provider's encryption modules under FIPS 140-3
Downgrade the confidentiality impact from high to moderate based on inherited FedRAMP controls
Conduct and publish a Privacy Impact Assessment for the new cloud system
The E-Government Act of 2002, implemented through OMB Memorandum M-03-22 and reinforced in OMB Circular A-130, requires federal agencies to complete a Privacy Impact Assessment (PIA) whenever a new system or major change will process personally identifiable information. The PIA documents what PII is collected, why it is collected, how it will be used, and what safeguards mitigate associated privacy risks, and it must be made publicly available with limited redactions. While CUI marking, FIPS 140-3 module validation, or adjusting FIPS 199 impact levels may also be part of an overall security approach, none of these actions are singled out by OMB as a mandatory pre-migration step for handling PII. Therefore, conducting and publishing a PIA is the correct requirement.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is a Privacy Impact Assessment (PIA)?
Open an interactive chat with Bash
What is FedRAMP and how does it relate to cloud services?
Open an interactive chat with Bash
What is the role of OMB guidance in federal information security and privacy?
Open an interactive chat with Bash
ISC2 Governance, Risk and Compliance (CGRC)
Scope of the System
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .