ISC2 Governance, Risk and Compliance (CGRC) Practice Question
While drafting the System Security Plan (SSP) for a new payroll platform, you reach the section that must articulate the organization's mission or business functions supported by the system. Which of the following statements best satisfies that requirement?
The platform consists of two Linux servers running PostgreSQL and an Nginx frontend located in the DMZ.
The platform is rated MODERATE for confidentiality and integrity and LOW for availability under FIPS 199.
The platform processes employee payroll, tax withholdings, and year-end reporting, enabling timely and accurate compensation that fulfills the organization's HR and financial accountability mission.
The platform synchronizes user credentials with Active Directory over LDAPS and encrypts data at rest using AES-256.
To meet the SSP requirement for describing the system's purpose and the mission or business functions it supports, the statement must explain why the system exists from an organizational perspective, not just list technical details or security categorization. The option describing how the platform processes employee payroll, tax withholdings, and year-end reporting-and how this enables the organization's HR and financial accountability mission-ties the system directly to core business operations. The other options focus on architecture, risk categorization, or specific technical controls; none of these explains the mission-driven purpose the system serves, so they do not fulfill the requirement.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is the purpose of a System Security Plan (SSP)?
Open an interactive chat with Bash
What is FIPS 199 and how does it relate to SSP development?
Open an interactive chat with Bash
Why is it important to align a system description with organizational mission in an SSP?
Open an interactive chat with Bash
ISC2 Governance, Risk and Compliance (CGRC)
Scope of the System
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .