ISC2 Governance, Risk and Compliance (CGRC) Practice Question
Under the NIST RMF, a security control assessor must remain independent of system design activities. Which assigned task would violate that independence and therefore be inappropriate for the assessor to perform during the system authorization effort?
Reviewing the completed system security plan to familiarize themselves with implemented controls.
Selecting and tailoring the baseline security and privacy controls for the system.
Delivering an assessment report with control deficiencies to the authorizing official.
Developing a security assessment plan that specifies test procedures and required evidence.
Independence of the security control assessor is required so the assessment remains objective. Selecting and tailoring the baseline controls is a system owner or information security officer responsibility performed earlier in the RMF. If the assessor chose the controls, they would be evaluating decisions they personally made, undermining impartiality. Reviewing the system security plan, building the security assessment plan, and delivering the final assessment report are all expected duties of the assessor and do not create a conflict of interest.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is the purpose of the NIST RMF?
Open an interactive chat with Bash
Why must the security control assessor remain independent?
Open an interactive chat with Bash
What are baseline controls in the RMF process?
Open an interactive chat with Bash
ISC2 Governance, Risk and Compliance (CGRC)
Security and Privacy Governance, Risk Management, and Compliance Program
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .