ISC2 Governance, Risk and Compliance (CGRC) Practice Question
Your agency intends to migrate a mission-support application to a FedRAMP-authorized SaaS provider. While establishing the compliance program with the NIST Risk Management Framework, which action belongs specifically in the Prepare step and helps you maximize use of inherited SaaS controls during later phases?
Tailor the NIST SP 800-53 moderate baseline to create the system's security control set.
Assign FIPS 199 impact levels to the application to determine security categorization.
Execute the security assessment plan to validate that provider controls are operating as intended.
Identify shared control providers and record common controls in the organization-wide control inventory.
During the Prepare step, organizations establish the foundational activities that will streamline later RMF tasks. One of those activities is identifying common controls and their providers so the system owner can inherit them instead of duplicating effort. Categorizing the system is performed in the separate Categorize step, tailoring baselines happens in the Select step, and executing the security assessment plan occurs in the Assess step. Therefore, documenting shared control providers during Prepare is the correct choice.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What are common controls in the NIST RMF?
Open an interactive chat with Bash
What is the significance of the Prepare step in the NIST RMF?
Open an interactive chat with Bash
How does inheriting SaaS controls benefit the RMF process?
Open an interactive chat with Bash
ISC2 Governance, Risk and Compliance (CGRC)
Security and Privacy Governance, Risk Management, and Compliance Program
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .