ISC2 Governance, Risk and Compliance (CGRC) Practice Question
During RMF Step 5 you are advising an Authorizing Official on whether to accept residual risk for an agency's new payment portal that will store cardholder primary account numbers. The system owner proposes leaving the data unencrypted because the assessed likelihood of compromise is low and encryption will delay deployment. Which explanation best justifies rejecting this risk-acceptance request?
Storing unencrypted PAN violates PCI DSS, which requires cardholder data to be unreadable at rest, so the risk cannot be accepted regardless of cost or schedule pressures.
FIPS 199 still needs to be applied to categorize the system; without that step no residual risk decision can be made, so acceptance is premature rather than impermissible.
OMB Circular A-123 requires financial risks to be transferred through insurance or contractual clauses, so acceptance is not an available option.
NIST SP 800-37 expressly prohibits accepting any residual confidentiality risk that is rated moderate or higher, mandating additional mitigation.
Risk acceptance decisions must honor mandatory regulatory requirements. The Payment Card Industry Data Security Standard (PCI DSS) Requirement 3 demands that primary account numbers be rendered unreadable (for example, by strong encryption) whenever stored. Because PCI DSS compliance is compulsory for any system that processes or stores cardholder data, the Authorizing Official cannot override this obligation simply by agreeing to accept the risk. The other statements are incorrect: FIPS 199 categorization would already have been completed in earlier RMF steps, NIST SP 800-37 does not forbid accepting moderate confidentiality risk, and OMB Circular A-123 addresses internal controls but does not require financial risks to be transferred.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is PCI DSS and why is it mandatory for systems handling cardholder data?
Open an interactive chat with Bash
What does RMF Step 5 entail in the risk management process?
Open an interactive chat with Bash
Why is encryption necessary for storing primary account numbers (PAN), and how does it comply with PCI DSS?
Open an interactive chat with Bash
ISC2 Governance, Risk and Compliance (CGRC)
System Compliance
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .