ISC2 Governance, Risk and Compliance (CGRC) Practice Question
Your agency's HR system will export employees' full names, Social Security numbers, and bank account numbers to a third-party payroll provider each pay period. According to federal PII handling requirements referenced in NIST SP 800-53 Rev. 5, what is the first control you should verify before the data is transmitted?
Confirm the file transfer is encrypted end-to-end with FIPS-validated cryptography.
Ensure a signed Memorandum of Understanding exists with the payroll provider.
Require the payroll provider to implement multi-factor authentication for administrators.
Apply a 90-day retention limit to the exported payroll files.
Personally identifiable information (PII) such as SSNs and bank details must be protected in transit with FIPS-validated cryptographic mechanisms. NIST SP 800-53 Rev. 5 control SC-13 (Cryptographic Protection) states that information requiring confidentiality must be encrypted during transmission. While agreements, MFA, and retention limits are also important, ensuring strong cryptographic protection is the prerequisite technical safeguard that must be confirmed before any data leaves the organization.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is FIPS-validated cryptography?
Open an interactive chat with Bash
How does NIST SP 800-53 Rev. 5 ensure PII protection during transmission?
Open an interactive chat with Bash
Why is encryption prioritized over other controls like agreements or MFA in this case?
Open an interactive chat with Bash
ISC2 Governance, Risk and Compliance (CGRC)
Selection and Approval of Framework, Security, and Privacy Controls
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .