ISC2 Governance, Risk and Compliance (CGRC) Practice Question
During the implementation phase of a newly selected set of NIST SP 800-53 controls, you must prove that each control has been put in place exactly as required by the approved System Security Plan (SSP). Which action best demonstrates that you are executing control implementation in strict alignment with all documented compliance requirements?
Allow administrators to tailor control settings during installation based on their individual preferences.
Defer detailed control configuration until after the authorizing official grants an ATO, then update the SSP.
Substitute required baseline controls with vendor-supplied features that seem stronger, without first revising the compliance documentation.
Verify each configured control against the specific implementation details recorded in the SSP before the system goes live.
Verifying that every configured control setting is compared against the parameters and implementation details recorded in the SSP shows direct alignment with documented compliance requirements. This step confirms that what was planned is what was actually deployed, making it possible for subsequent assessors to validate the implementation. Merely relying on administrator preference, postponing tuning until after authorization, or changing controls without first updating documentation all break the traceability needed for compliant implementation and could introduce unvetted risk.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is NIST SP 800-53?
Open an interactive chat with Bash
What is the System Security Plan (SSP)?
Open an interactive chat with Bash
What is the Authorization to Operate (ATO)?
Open an interactive chat with Bash
ISC2 Governance, Risk and Compliance (CGRC)
Implementation of Security and Privacy Controls
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .