ISC2 Governance, Risk and Compliance (CGRC) Practice Question
During scoping for a compliance assessment, your team debates including the externally hosted CRM SaaS that exchanges customer PII with on-premises systems. Which factor provides the strongest justification for keeping the SaaS in scope?
The SaaS provider, not the organization, owns and manages the underlying hardware.
Its servers are physically located outside the corporate data center.
The service processes and stores regulated customer data integral to business workflows.
Collecting audit evidence from a SaaS vendor will lengthen the project schedule.
Scope is defined by whether a component processes, stores, or transmits organizational information that is subject to the assessment objectives. Because the CRM SaaS handles regulated customer data and ties directly into core business workflows, it must be considered part of the system boundary. Physical location and ownership of hardware do not remove compliance obligations, and the difficulty or cost of evidence collection does not determine scope.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What does it mean for a system to be 'in scope' during a compliance assessment?
Open an interactive chat with Bash
Why does regulated customer data impact whether a service is in scope?
Open an interactive chat with Bash
Why are physical location and ownership of hardware not determining factors for compliance scope?
Open an interactive chat with Bash
Why does handling regulated customer data make the CRM SaaS part of the compliance scope?
Open an interactive chat with Bash
What does ‘system boundary’ mean in compliance assessments?
Open an interactive chat with Bash
Why doesn’t physical location or hardware ownership affect compliance obligations?
Open an interactive chat with Bash
ISC2 Governance, Risk and Compliance (CGRC)
Assessment/Audit of Security and Privacy Controls
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .