ISC2 Governance, Risk and Compliance (CGRC) Practice Question
After selecting mitigation for a critical injection vulnerability in a custom web service, the risk management team must estimate the staff hours and expertise required to rewrite and test the affected modules. Which stakeholder should they engage first to obtain realistic personnel estimates and scheduling data?
The application development lead responsible for the service
The application development lead (or equivalent system developer manager) has direct knowledge of the codebase, team capacity, and the skills needed to correct and retest the modules. This individual can supply accurate effort estimates that feed the risk response plan's personnel and timeline section. A CISO provides policy direction but not task-level resource figures, a procurement officer focuses on acquisition contracts rather than internal labor estimates, and an internal audit manager validates controls after implementation rather than planning technical remediation work.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
Why is the application development lead the correct stakeholder to engage?
Open an interactive chat with Bash
What is the role of the Chief Information Security Officer (CISO) in this process?
Open an interactive chat with Bash
Why wouldn't the internal audit manager be the right stakeholder for this task?
Open an interactive chat with Bash
ISC2 Governance, Risk and Compliance (CGRC)
Assessment/Audit of Security and Privacy Controls
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .