ISC2 Governance, Risk and Compliance (CGRC) Practice Question
While compiling the authorization package for a newly assessed moderate-impact system, the security team has already attached the finalized System Security Plan, Security Assessment Report, and Plan of Action and Milestones. Which additional document should they include before submitting the package to the authorizing official so that the official has a concise statement of the requested decision and a synopsis of residual risk?
The complete continuous monitoring strategy that will be executed after deployment
The detailed network boundary diagram used during security control selection
The current secure configuration baseline for all production servers
A signed authorization request letter that briefly explains mission needs and summarizes residual risk
NIST SP 800-37 Rev. 2 states that, in addition to the System Security Plan, Security Assessment Report, and POA&M, the package normally contains a formal authorization request (often called an executive summary or risk-based recommendation). This letter, signed by the system owner or senior information security officer, summarizes the system's mission, residual risk, and any terms or conditions being requested. It gives the authorizing official the context needed to issue an Authorization to Operate or other decision. Items such as boundary diagrams, configuration baselines, or full continuous-monitoring strategies are important artifacts but are not the document specifically intended to request and justify the authorization decision.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is the authorization request letter used for?
Open an interactive chat with Bash
Why is residual risk important in an authorization decision?
Open an interactive chat with Bash
Why are items like boundary diagrams and continuous monitoring strategies not included as the decision document?
Open an interactive chat with Bash
ISC2 Governance, Risk and Compliance (CGRC)
System Compliance
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .