ISC2 Governance, Risk and Compliance (CGRC) Practice Question
A lead assessor has finished drafting a NIST SP 800-53 security control assessment plan for a newly deployed HR system. The draft consolidates objectives, scope boundaries, assessment procedures, resource needs, schedule, and deliverables. According to accepted audit-planning practice, which additional action officially finalizes the assessment plan so the team can start fieldwork?
Obtaining formal written approval and sign-off on the documented plan from the authorizing official and other key stakeholders
Collecting preliminary evidence such as prior audit reports and network diagrams for scope familiarization
Purchasing additional vulnerability-scanning tool licenses required for technical testing during fieldwork
Compiling objectives, boundaries, milestones, resource commitments, and assessment methods into a single formal document
Under NIST SP 800-53A and general audit-planning guidance, an assessment plan is only considered final after the documented plan has been reviewed and given written approval by the authorizing official and other key stakeholders. Compiling the plan, gathering preliminary evidence, buying tools, or performing follow-up tests are useful steps, but none of them substitutes for the required management sign-off that makes the plan authoritative and ready for execution.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is NIST SP 800-53?
Open an interactive chat with Bash
Why is formal written approval necessary to finalize an assessment plan?
Open an interactive chat with Bash
What is the role of an authorizing official in audit planning?
Open an interactive chat with Bash
ISC2 Governance, Risk and Compliance (CGRC)
Assessment/Audit of Security and Privacy Controls
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .