ISC2 Governance, Risk and Compliance (CGRC) Practice Question
Your agency is deploying a new cloud-hosted payroll application. The system security engineer must decide which NIST SP 800-53 controls the payroll system can inherit as common controls versus those it must implement itself. Which of the following controls is most appropriately treated as a common control that the payroll system can inherit?
Full-disk encryption software installed only on laptops issued to payroll clerks
Input validation checks performed by the payroll database's stored procedures
Continuous 24x7 monitoring and incident response services provided by the enterprise Security Operations Center
Role-based access permissions configured within the payroll application's administrative console
Common controls are security or privacy safeguards implemented at an organizational level and available for multiple information systems to inherit. An enterprise Security Operations Center that provides 24x7 security monitoring and incident response meets this definition because a single, centrally managed capability protects every system connected to the network. In contrast, application-specific role-based permissions, database input validation routines, or encryption installed only on a particular set of laptops are implemented for a limited set of assets and therefore are system-specific or device-specific controls, not common controls.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is a common control according to NIST SP 800-53?
Open an interactive chat with Bash
How does an enterprise Security Operations Center contribute as a common control?
Open an interactive chat with Bash
Can role-based access permissions ever be considered as a common control?
Open an interactive chat with Bash
ISC2 Governance, Risk and Compliance (CGRC)
Implementation of Security and Privacy Controls
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .