ISC2 Governance, Risk and Compliance (CGRC) Practice Question
After receiving an Authorization Decision Document that grants an ATO with conditions requiring three medium vulnerabilities to be fixed within 90 days, what should the ISSO do first to properly document the system's compliance status?
Archive the authorization letter and mark the outstanding POA&M items as already mitigated.
Submit a waiver request to postpone all remediation actions until after the ATO expires.
Return the authorization package to the assessor and request an immediate new security assessment.
Record the required fixes and deadlines in the POA&M and distribute the authorization letter to all identified stakeholders.
The authorization decision is not complete until its terms and conditions are reflected in the system's compliance records and shared with affected parties. The Plan of Action and Milestones (POA&M) is the official document for recording required remediation activities, target dates, and responsible parties. Entering the new corrective actions in the POA&M and circulating the signed authorization letter to system and business stakeholders ensures that everyone is aware of the residual risk and the deadlines established by the authorizing official. Simply archiving the letter, requesting new assessments, or asking for waivers does not meet RMF requirements for documenting compliance.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is a Plan of Action and Milestones (POA&M)?
Open an interactive chat with Bash
What does Authorization to Operate (ATO) mean in RMF?
Open an interactive chat with Bash
What role does an Information System Security Officer (ISSO) play in compliance documentation?
Open an interactive chat with Bash
ISC2 Governance, Risk and Compliance (CGRC)
System Compliance
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .