ISC2 Governance, Risk and Compliance (CGRC) Practice Question
While tailoring the NIST SP 800-53 Rev.5 moderate baseline for a new SaaS application, you confirm that AC-6(9) (audit of privileged actions) is fully implemented by the FedRAMP-authorized cloud service provider through its management plane. The system owner wants to mark the enhancement "not applicable." What is the BEST way to address this control during selection and tailoring?
List AC-6(9) as a compensating control and create a POA&M item for on-premises implementation at a later date.
Remove AC-6(9) from the baseline because the enhancement is above the minimum requirements for moderate systems.
Document AC-6(9) as an inherited control in the SSP and reference the provider's authorization package for evidence.
Formally accept the residual risk and leave AC-6(9) marked "not applicable" in the SSP.
Because the cloud service provider already implements AC-6(9), the control is applicable to the system but its responsibility is inherited from the provider. The proper action is to record it as an inherited control in the System Security Plan and reference the provider's FedRAMP authorization package for evidence. Removing it as "not applicable," treating it as a compensating control, or simply accepting risk would leave the control undocumented or mis-categorized and could create gaps in assessment and authorization activities.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What does AC-6(9) (audit of privileged actions) entail?
Open an interactive chat with Bash
What is FedRAMP and its relevance to AC-6(9)?
Open an interactive chat with Bash
What is an inherited control in the SSP?
Open an interactive chat with Bash
ISC2 Governance, Risk and Compliance (CGRC)
Selection and Approval of Framework, Security, and Privacy Controls
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .