ISC2 Governance, Risk and Compliance (CGRC) Practice Question
Your federal agency plans to let a private contractor operate a system that will process agency-owned data. According to FISMA requirements, which action must the agency take before allowing the contractor to begin operations?
Transfer full responsibility for any future security incidents to the contractor through a service-level agreement.
Obtain prior approval from the Government Accountability Office before any agency information is processed off-site.
Verify that the contractor's system implements security controls that provide protection equivalent to the level the agency applies to its own systems and data.
Publish a detailed description of the system's security architecture in the Federal Register for public comment.
FISMA extends an agency's information-security responsibilities to any information system that is "used or operated by a contractor of an agency or other organization on behalf of an agency". The agency head must therefore ensure that the contractor's system receives security protections commensurate with the risk and comparable to those applied to government-operated systems. Merely publishing notices, shifting liability through contracts, or seeking external approval are not mandated by the statute. FISMA keeps accountability within the agency and requires equivalent protections, not procedural formalities that delegate or transfer responsibility.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is FISMA and why is it important?
Open an interactive chat with Bash
What does 'security protections commensurate with the risk' mean in FISMA?
Open an interactive chat with Bash
How do agencies verify contractor systems meet FISMA requirements?
Open an interactive chat with Bash
ISC2 Governance, Risk and Compliance (CGRC)
Security and Privacy Governance, Risk Management, and Compliance Program
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .