ISC2 Governance, Risk and Compliance (CGRC) Practice Question

During a security authorization effort, the assessment team documents several moderate residual risks that still exceed the system owner's risk tolerance. The owner asks to accept these risks to avoid mission delay. Before the POA&M is closed, which stakeholder's formal concurrence is required to legitimize the risk-acceptance decision?

  • The Security Control Assessor (SCA)

  • The Information System Security Officer (ISSO)

  • The Chief Information Officer (CIO)

  • The Authorizing Official with responsibility for the information system

ISC2 Governance, Risk and Compliance (CGRC)
System Compliance
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot