ISC2 Governance, Risk and Compliance (CGRC) Practice Question
Your agency categorizes a new information system as low impact for confidentiality, integrity, and availability under FIPS 199. When you consult the low-impact baseline in NIST SP 800-53B (which is derived from the SP 800-53 Revision 5 control catalog), which statement best describes how that baseline is assembled?
It contains the minimum set of foundational controls from every family with no control enhancements included.
It relies exclusively on privacy or industrial-control overlays to build the complete set of required controls.
It excludes entire control families such as Incident Response and Audit because of the system's low impact rating.
It starts with moderate-baseline controls and then removes any that are not applicable to the system.
NIST SP 800-53B lists the low-impact baseline as the smallest set of foundational security and privacy controls needed for federal information systems. Every one of the 20 control families is represented, but the baseline contains only the basic (base) versions of those controls and no control enhancements. Organizations may add enhancements or overlays later through tailoring if their risk assessment shows the need. Therefore, the most accurate description is that the baseline is the minimum set of foundational controls with no enhancements included. The other statements are incorrect because the low baseline does not begin with the moderate set of controls, does not drop whole control families, and is not built solely from overlays.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is FIPS 199 and how does it relate to categorizing information systems?
Open an interactive chat with Bash
What are control families in NIST SP 800-53?
Open an interactive chat with Bash
What is the difference between a control baseline and an overlay in NIST SP 800-53?
Open an interactive chat with Bash
ISC2 Governance, Risk and Compliance (CGRC)
Selection and Approval of Framework, Security, and Privacy Controls
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .