ISC2 Governance, Risk and Compliance (CGRC) Practice Question
While performing the Select security controls step of the NIST Risk Management Framework, you learn that the new information system will operate in a strictly controlled data-center where visitors are never permitted. To justify removing control PE-16 (Visitor Access Records) from the initial Moderate baseline, which tailoring activity defined by NIST SP 800-53 should you document?
Set the organization-defined parameters in PE-16 to values that effectively disable its requirements.
Document a scoping consideration that the operational environment makes the control inapplicable.
Replace PE-16 with a compensating control that provides equivalent protection.
Apply a privacy overlay that excludes PE-16 from the Moderate baseline.
NIST SP 800-53 states that the first tailoring activity is to apply scoping considerations. Scoping lets an organization determine whether a baseline control is applicable, based on factors such as the system's operational environment, technology, or mission needs. Because the facility never allows visitors, PE-16 does not apply, and its removal can be justified through scoping.
Assigning organization-defined parameter values is parameterization, which modifies how a control is implemented but does not remove it. Compensating controls are added when the original control cannot be met, not when it is unnecessary. Overlays add or refine controls for specific technologies or communities of interest rather than removing them.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What are scoping considerations in NIST SP 800-53?
Open an interactive chat with Bash
How does parameterization differ from scoping in NIST SP 800-53?
Open an interactive chat with Bash
What are compensating controls, and when are they used in the Risk Management Framework?
Open an interactive chat with Bash
ISC2 Governance, Risk and Compliance (CGRC)
Security and Privacy Governance, Risk Management, and Compliance Program
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .