ISC2 Governance, Risk and Compliance (CGRC) Practice Question

While conducting the scoping and applicability analysis for a new public-facing website that publishes only publicly releasable data, the security architect reviews control SC-13 (Cryptographic Protection) from the NIST SP 800-53 moderate baseline. Which justification best supports marking this control as Not Applicable in the System Security Plan (SSP)?

  • The information handled has a low confidentiality impact because it is publicly releasable, so protecting it with cryptography is unnecessary.

  • Project funding for encryption capabilities was deferred to the next budget cycle, making near-term implementation impractical.

  • The commercial off-the-shelf web server software selected for the project does not support encryption without extra modules.

  • The cloud service provider already implements encryption for its infrastructure under a FedRAMP authorization.

ISC2 Governance, Risk and Compliance (CGRC)
Selection and Approval of Framework, Security, and Privacy Controls
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot