ISC2 Governance, Risk and Compliance (CGRC) Practice Question
During a quarterly internal assessment, the compliance team must show auditors that the organization's change control process for a high-availability payment platform is operating effectively. Which of the following provides the most persuasive evidence that every production change is being reviewed and approved according to policy?
Attendance logs confirming staff completion of annual security and privacy awareness training
Automated vulnerability scan reports generated after each maintenance window
Signed minutes from each Change Control Board meeting documenting the approval or rejection of every production change request, including approver names and dates
Performance monitoring dashboards showing CPU and memory utilization trends for production servers
Effective monitoring of a change control process requires proof that each change was formally evaluated and approved before implementation. Meeting minutes or logs from the Change Control Board (CCB) that list individual change requests, the approvers' names, dates, decisions, and any required rollback plans directly demonstrate that the prescribed review and authorization steps were executed. Vulnerability scans, performance dashboards, and training attendance records are useful for other compliance areas, but they do not verify that specific production changes went through the mandated approval workflow, so they are weaker or irrelevant evidence for assessing change-control effectiveness.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is a Change Control Board (CCB)?
Open an interactive chat with Bash
Why are meeting minutes considered persuasive evidence for change control effectiveness?
Open an interactive chat with Bash
How does the compliance team ensure the change control process aligns with policy?
Open an interactive chat with Bash
ISC2 Governance, Risk and Compliance (CGRC)
Compliance Maintenance
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .