ISC2 Governance, Risk and Compliance (CGRC) Practice Question
While drafting the control implementation strategy for a new cloud-based CRM, the security project lead is told to validate that proposed safeguards stay within the organization's accepted risk levels. Which internal artifact should the lead consult first to understand the enterprise's overall risk tolerance?
The organization's enterprise risk appetite or risk tolerance statement approved by executive leadership
The information system contingency plan for the CRM platform
The configuration-management plan that governs changes to the CRM
The system security plan (SSP) for the CRM environment
A formally approved risk appetite (or enterprise risk statement) articulates the amount and type of risk senior leadership is prepared to accept in pursuit of business objectives. Referencing this statement allows the project lead to judge whether the controls, their rigor, and their residual risks align with organizational expectations. A system security plan focuses on one system's controls, not enterprise-wide tolerance. A configuration-management plan details how system changes are handled but does not define acceptable risk levels. An information system contingency plan describes recovery steps after a disruption, not the organization's overarching risk appetite.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is a risk appetite?
Open an interactive chat with Bash
How does a system security plan (SSP) differ from a risk appetite statement?
Open an interactive chat with Bash
Why aren't configuration-management and contingency plans used to determine risk tolerance?
Open an interactive chat with Bash
ISC2 Governance, Risk and Compliance (CGRC)
Implementation of Security and Privacy Controls
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .