ISC2 Governance, Risk and Compliance (CGRC) Practice Question
While conducting the scoping and applicability analysis for a new public-facing website that publishes only publicly releasable data, the security architect reviews control SC-13 (Cryptographic Protection) from the NIST SP 800-53 moderate baseline. Which justification best supports marking this control as Not Applicable in the System Security Plan (SSP)?
The information handled has a low confidentiality impact because it is publicly releasable, so protecting it with cryptography is unnecessary.
Project funding for encryption capabilities was deferred to the next budget cycle, making near-term implementation impractical.
The commercial off-the-shelf web server software selected for the project does not support encryption without extra modules.
The cloud service provider already implements encryption for its infrastructure under a FedRAMP authorization.
SC-13 requires protecting the confidentiality and integrity of information in transit or at rest with approved cryptography. During scoping, a control may be designated Not Applicable only when the system's security categorization or design characteristics show that the control's purpose is not relevant. Because the website processes and transmits information that is already public, the confidentiality impact level is low, and there is no security objective to preserve the secrecy of the data. In that case, the requirement to apply cryptographic protection to the data can legitimately be scoped out. Relying on a cloud provider (inherited control), product limitations, or budget constraints do not eliminate the need for the control; they merely shift implementation responsibility or require alternative solutions, so those reasons would not justify an N/A determination.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is SC-13 and why is it important in the context of NIST SP 800-53?
Open an interactive chat with Bash
What criteria determine if a control can be marked as Not Applicable in the SSP?
Open an interactive chat with Bash
What is the relationship between inherited controls and marking a control as Not Applicable?
Open an interactive chat with Bash
What does 'SC-13 Cryptographic Protection' entail?
Open an interactive chat with Bash
How does scoping determine if a control is 'Not Applicable'?
Open an interactive chat with Bash
What is the difference between an inherited control and scoping out a control?
Open an interactive chat with Bash
ISC2 Governance, Risk and Compliance (CGRC)
Selection and Approval of Framework, Security, and Privacy Controls
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .