ISC2 Governance, Risk and Compliance (CGRC) Practice Question
During development of a mission-critical federal payroll system, the security team determines the information type is High for confidentiality, integrity, and availability under FIPS 199. When defining the initial security control baseline in the System Security Plan (SSP) using NIST SP 800-53 Rev. 5, which approach BEST reflects how a high-impact baseline is constructed?
Start with the low baseline, incorporate every control from the low and moderate baselines, and then add the additional controls and enhancements designated for high-impact systems.
Begin with the moderate baseline and add only those control enhancements the authorizing official deems cost-effective for the project.
Replace the security baseline with the NIST privacy overlay, since high-impact systems always process personally identifiable information (PII).
Select controls that mitigate confidentiality threats, because availability and integrity are already protected by the organization's common controls.
The NIST SP 800-53 high-impact baseline is cumulative; it begins with every control required for the low-impact baseline, adds all controls and enhancements from the moderate baseline, and then layers on additional controls and stronger enhancements that address the more severe consequences associated with a catastrophic loss of confidentiality, integrity, or availability. Selecting only confidentiality controls or swapping in a privacy overlay would leave significant gaps, and starting solely from the moderate baseline without adding the high-specific controls would be incomplete. Therefore, the correct practice is to inherit the entire set of low and moderate controls and then add the high-impact-specific requirements.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is FIPS 199 and how does it classify information types?
Open an interactive chat with Bash
What is NIST SP 800-53 Rev. 5 used for in federal systems?
Open an interactive chat with Bash
What is the System Security Plan (SSP) and its role in federal systems security?
Open an interactive chat with Bash
ISC2 Governance, Risk and Compliance (CGRC)
Selection and Approval of Framework, Security, and Privacy Controls
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .