ISC2 Governance, Risk and Compliance (CGRC) Practice Question
During a security control assessment of a newly deployed payment platform, you have finished interviews, document reviews, and technical testing. Before sending the draft security assessment report to the system owner, what is the most effective way to record your preliminary findings so they reflect both compliant and non-compliant controls?
Draft an executive summary that describes only the highest-risk deficiencies identified during testing.
Populate a findings matrix that lists every assessed control, its compliance status, and supporting evidence references.
Attach the raw vulnerability scan output as an appendix and postpone control status analysis until the final report.
Compile interview notes into a narrative section and wait for peer review to decide which controls were compliant.
A control-by-control findings matrix forces the assessor to document every evaluated control, indicate whether it is compliant, non-compliant, or not applicable, and reference the evidence collected. This format ensures that strengths as well as deficiencies are captured up front, satisfying the requirement to record all preliminary findings. Limiting the write-up to an executive summary would omit many compliant controls, while dumping raw scan output or unfiltered interview notes provides data without clearly stating each control's status, making it hard for stakeholders to understand the results.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is a findings matrix in the context of security assessments?
Open an interactive chat with Bash
Why is a findings matrix better than raw vulnerability scan outputs or unfiltered interview notes?
Open an interactive chat with Bash
How does a findings matrix satisfy preliminary reporting requirements effectively?
Open an interactive chat with Bash
ISC2 Governance, Risk and Compliance (CGRC)
Assessment/Audit of Security and Privacy Controls
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .