ISC2 Governance, Risk and Compliance (CGRC) Practice Question
While compiling the System Security Plan (SSP) for a new low-impact public-facing web application that will be hosted entirely in a FedRAMP-authorized Infrastructure as a Service (IaaS) environment, you must indicate which controls are inherited from the cloud service provider. Which of the following controls should you record in the SSP as inherited rather than system-specific or hybrid?
Weekly audit log review performed by the information system security officer
Physical access controls enforced at the cloud provider's data center
Server-side input validation routines coded into the web application
Web server session timeout configured by the system administrator
Inherited controls are those that the information system receives from an external provider-often a common control provider such as a cloud service-without additional implementation effort by the system owner. Physical and environmental protection measures (e.g., facility access control, power, HVAC, fire suppression) are typically implemented, managed, and assessed by the data-center provider. Because the web application team neither designs nor operates these safeguards, the SSP should mark them as inherited. In contrast, application input validation, session timeout settings, and audit log review are performed by the system's development or operations staff; therefore they are system-specific or, if partially shared, hybrid controls, not inherited ones.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What are inherited controls in the context of FedRAMP?
Open an interactive chat with Bash
What is the System Security Plan (SSP) and why is it important?
Open an interactive chat with Bash
How does FedRAMP define the difference between inherited and system-specific controls?
Open an interactive chat with Bash
ISC2 Governance, Risk and Compliance (CGRC)
Selection and Approval of Framework, Security, and Privacy Controls
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .