ISC2 Governance, Risk and Compliance (CGRC) Practice Question
During pre-audit preparation, you are reviewing the system security plan (SSP) for a moderate-impact information system that recently migrated several components to a cloud service provider. Which action best demonstrates that the documentation is current, accurate, and complete before it is submitted to auditors?
Delete references to decommissioned on-premises servers from the asset inventory appendix without further validation.
Attach the prior year's penetration-test report to the SSP as supplemental evidence of security control effectiveness.
Create a POA&M item stating that architecture diagrams will be updated after the audit is complete.
Revise the SSP diagrams to show the cloud components and obtain the Authorizing Official's signature on the updated version.
Updating the SSP's architecture, network, and data-flow diagrams to include the new cloud services-and then obtaining the Authorizing Official's formal approval-shows that the plan reflects the system's actual configuration and that accountable leadership accepts the changes. NIST requires security documentation to be updated whenever significant modifications occur and to be re-approved by the Authorizing Official before an audit. Simply adding a future POA&M entry, attaching an old penetration-test report, or deleting assets without verification does not meet NIST's standards for completeness and accuracy.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is the purpose of a System Security Plan (SSP) in compliance frameworks like NIST?
Open an interactive chat with Bash
Why is the Authorizing Official's signature an important step in updating the SSP?
Open an interactive chat with Bash
What are the NIST requirements for updating security documentation after system modifications?
Open an interactive chat with Bash
ISC2 Governance, Risk and Compliance (CGRC)
Compliance Maintenance
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .