ISC2 Governance, Risk and Compliance (CGRC) Practice Question
While preparing the SSP for a FISMA-moderate web service hosted in a FedRAMP Moderate IaaS, you analyze NIST SP 800-53 control PE-3 (Physical Access Control). The provider owns and documents all facility protections in its customer responsibility matrix. How should PE-3 be recorded in your SSP?
List PE-3 as system-specific since all Moderate-baseline controls must appear in every SSP.
Record PE-3 as an inherited control and reference the provider's FedRAMP package.
Remove PE-3 from the baseline, noting it is not applicable to virtualized workloads.
Classify PE-3 as a hybrid control because administrators still request badge access to visit the facility.
Because the IaaS provider fully implements and documents PE-3 for its data centers, the web service inherits the control from a common control provider. In the SSP you would mark PE-3 as "Inherited" and reference the provider's FedRAMP security package. Labeling it hybrid would only apply if both parties shared implementation duties; designating it system-specific ignores the common-control construct; removing it as not applicable violates the Moderate baseline, which still requires physical protection even for virtual workloads.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is an SSP in relation to FISMA compliance?
Open an interactive chat with Bash
What does it mean for a control to be inherited in NIST SP 800-53?
Open an interactive chat with Bash
Why does the Moderate baseline require physical protection for virtual workloads?
Open an interactive chat with Bash
ISC2 Governance, Risk and Compliance (CGRC)
Selection and Approval of Framework, Security, and Privacy Controls
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .