ISC2 Governance, Risk and Compliance (CGRC) Practice Question
While drafting the initial assessment report, an assessor must convert technical control deficiencies into risk statements that management can act on. According to NIST risk assessment guidance, which element is mandatory in every such risk statement to ensure it can drive later risk response planning?
Reference to the control family in which the deficiency was found
A detailed cost estimate for fully remediating the control weakness
Identification of the assessor who discovered the weakness during testing
A description of how a threat could exploit a specific vulnerability and the resulting impact
NIST SP 800-30 explains that an actionable risk statement should clearly link a threat, the vulnerability it could exploit, and the potential adverse impact. Without this cause-and-effect description, decision makers cannot judge likelihood or consequences, making remediation prioritization difficult. Cost estimates, assessor names, or control families may be useful ancillary information, but they are not required components of the risk statement itself.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is NIST SP 800-30?
Open an interactive chat with Bash
What is the difference between a vulnerability and a threat?
Open an interactive chat with Bash
Why is a cause-and-effect description important in a risk statement?
Open an interactive chat with Bash
ISC2 Governance, Risk and Compliance (CGRC)
Assessment/Audit of Security and Privacy Controls
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .