ISC2 Governance, Risk and Compliance (CGRC) Practice Question
While drafting the SSP for a new SaaS-based HR application, you learn the cloud provider operates the network boundary firewall and maintains core rule sets, but your team must configure application-level rules within each container. How should this control be recorded in the inheritance table?
Record it as a system-specific control implemented entirely by the HR application team.
Record it as a hybrid control that is shared between the cloud provider and the system owner.
Record it as a common control available to all organizational systems.
Record it as an inherited control fully provided by the cloud service provider.
Because responsibility for the firewall is split-basic infrastructure and baseline rules from the provider, application-specific rules from the system owner-the control is only partially inherited. NIST defines such a partially provided, partially system-specific safeguard as a hybrid control. Labeling it hybrid in the SSP makes clear which tasks belong to the provider and which belong to the HR team. Classifying it as fully system-specific, fully inherited, or a common control would overlook this shared implementation and obscure accountability.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is an SSP and why is it important?
Open an interactive chat with Bash
What is a hybrid control in NIST terminology?
Open an interactive chat with Bash
How does inheriting controls differ from implementing system-specific ones?
Open an interactive chat with Bash
ISC2 Governance, Risk and Compliance (CGRC)
Selection and Approval of Framework, Security, and Privacy Controls
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .