ISC2 Governance, Risk and Compliance (CGRC) Practice Question
During an authorization review you discover that nightly database backups for a SaaS application are stored in plaintext in an external object store. The system owner asks what action should be entered in the POA&M so stakeholders can approve the organization's plan to mitigate (not merely accept, transfer, or avoid) the risk. Which option best represents risk mitigation?
Note the issue as within the agency's risk tolerance and request the AO accept it unchanged.
Implement server-side encryption for all backups and include completion dates in the POA&M.
Sign a cyber-insurance rider covering disclosure of backup data.
Suspend all backup operations until a new solution is procured.
Mitigation seeks to reduce either the likelihood or impact of a threat by adding or improving safeguards. Encrypting all backups introduces a technical control that directly reduces the probability and consequence of unauthorized disclosure; documenting the task, responsible party, and due date in the POA&M demonstrates a concrete plan for remediation. Purchasing cyber-insurance transfers financial consequences rather than reducing the vulnerability. Formally noting the issue for the authorizing official without changing controls is risk acceptance. Suspending all backups removes the specific exposure but also eliminates the ability to recover data; it therefore shifts rather than accepts or transfers risk and is considered an extreme form of mitigation, not the preferred treatment here.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is a POA&M in risk management?
Open an interactive chat with Bash
Why is encryption important in mitigating data disclosure risks?
Open an interactive chat with Bash
What differentiates risk mitigation from risk acceptance, transfer, or avoidance?
Open an interactive chat with Bash
ISC2 Governance, Risk and Compliance (CGRC)
System Compliance
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .