ISC2 Governance, Risk and Compliance (CGRC) Practice Question
During preparation for a controls assessment of a cloud-hosted payroll system, the assessor begins gathering documentation to establish preliminary evidence of compliance. Which document should be examined first because it fully describes the system environment and the planned security controls?
Latest automated configuration baseline snapshot of production servers
Signed Authorization to Operate letter issued by the Authorizing Official
Current Plan of Action and Milestones detailing outstanding findings
A System Security Plan (SSP) is the foundational document in the Risk Management Framework that details the system's boundaries, operational environment, and every security control selected or implemented. Assessors rely on the SSP to understand how the organization intends to meet each control requirement before they decide what additional evidence, interviews, or technical tests are necessary. A Plan of Action and Milestones focuses only on outstanding deficiencies and does not provide a complete control picture. An Authorization to Operate letter merely records the authorizing official's decision and gives no detail about control implementation. A configuration baseline snapshot is useful for technical verification but lacks the broader context of all administrative, technical, and managerial controls. Therefore, reviewing the SSP first gives the assessor the most comprehensive starting point for evaluating compliance.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is the purpose of a System Security Plan (SSP)?
Open an interactive chat with Bash
What is the Risk Management Framework (RMF)?
Open an interactive chat with Bash
How does an SSP differ from a Plan of Action and Milestones (POA&M)?
Open an interactive chat with Bash
ISC2 Governance, Risk and Compliance (CGRC)
Assessment/Audit of Security and Privacy Controls
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .