ISC2 Governance, Risk and Compliance (CGRC) Practice Question
While preparing a System Security Plan (SSP) for a new FISMA-moderate system, you find that an enterprise IAM service will satisfy most requirements of control AC-2 (Account Management). According to NIST SP 800-18, what must you record in the SSP for AC-2 so assessors understand its implementation?
List AC-2 only in the baseline summary table since its selection is predetermined for moderate systems, omitting further explanation.
Place details about AC-2 in the contingency planning appendix along with recovery objectives, leaving the main SSP control section blank.
Mark AC-2 as not applicable and reference the enterprise identity service to show it is already addressed elsewhere.
Identify the control's origination as hybrid, name the common control provider, and describe which portions of AC-2 are inherited versus system-specific.
NIST SP 800-18 Rev. 1 states that each security control entry in an SSP must identify the control's origination-system-specific, common, or hybrid-and describe how it is implemented. Because most AC-2 requirements are delivered by an enterprise IAM service, the SSP must label AC-2 as a hybrid control, name the IAM service as the common-control provider, and explain which elements of the control are inherited versus handled locally. Simply marking the control not applicable or moving the information elsewhere would fail to show who is responsible for the inherited and system-specific portions.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What does AC-2 (Account Management) address in terms of security controls?
Open an interactive chat with Bash
What is a hybrid control under NIST SP 800-18?
Open an interactive chat with Bash
What role does the SSP play in documenting security controls like AC-2?
Open an interactive chat with Bash
ISC2 Governance, Risk and Compliance (CGRC)
Selection and Approval of Framework, Security, and Privacy Controls
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .