ISC2 Governance, Risk and Compliance (CGRC) Practice Question
During the RMF Select step, your team decides that AC-11 (Session Lock) is not applicable because the fielded sensor platform has no local console or user interface. According to NIST guidance on documenting tailoring, what must be captured in the System Security Plan (SSP) to justify the removal of this baseline control?
A note that the control will be implemented in a later phase and added to the POA&M.
The projected implementation cost and the savings realized by omitting the control.
A generic statement that the organization's overarching security policy overrides the baseline.
A risk-based technical justification that explains why the control is unnecessary given the system's mission, operating environment, and accepted residual risk.
NIST SP 800-37 Rev. 2 (Task 2-2) and SP 800-53B both require that any tailoring action-whether non-applicability, scoping, or compensating-be recorded in the SSP with a clear, risk-based justification tied to the system's function, environment, and mission/business needs. Merely citing cost, deferring the control, or referencing a blanket policy does not satisfy the requirement because those statements do not demonstrate why the control is technically unnecessary or how the residual risk is being accepted.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is RMF tailoring?
Open an interactive chat with Bash
What is the System Security Plan (SSP)?
Open an interactive chat with Bash
What is residual risk in the context of RMF?
Open an interactive chat with Bash
ISC2 Governance, Risk and Compliance (CGRC)
Selection and Approval of Framework, Security, and Privacy Controls
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .