ISC2 Governance, Risk and Compliance (CGRC) Practice Question
While drafting the System Security Plan for a new web-based employee benefits portal, which of the following pieces of information best satisfies the requirement to describe the system's overall purpose and functionality from a business and operational perspective?
A narrative explaining how the portal enables employees to enroll in benefits, identifies its primary user groups, and summarizes key functions such as payroll data exchange and HR reporting.
The most recent vulnerability scan results with associated findings and remediation deadlines.
A network topology diagram that maps routers, switch ports, and firewall access control lists protecting the data center.
A detailed inventory of each server's IP address, operating system version, and applied security patches.
NIST SP 800-18 Rev. 1 directs preparers of a System Security Plan to include a high-level description of the system that explains what mission or business processes it supports, who uses it, and the major functions it performs. Providing a concise narrative that links the portal to employee onboarding and open-enrollment activities, identifies its primary users (employees and HR staff), and summarizes key capabilities (benefit selection, payroll data exchange, reporting) addresses exactly that requirement. Detailed technical artifacts-such as IP address inventories, network topology diagrams, or vulnerability scan results-belong in other sections of the SSP or in supporting documents; they do not by themselves convey the system's business purpose and operational function.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is NIST SP 800-18 Rev. 1?
Open an interactive chat with Bash
Why is a high-level narrative more suitable than technical artifacts in a System Security Plan?
Open an interactive chat with Bash
What are the key components of a System Security Plan (SSP)?
Open an interactive chat with Bash
What is NIST SP 800-18 Rev. 1?
Open an interactive chat with Bash
Why is the system’s business purpose important in the SSP?
Open an interactive chat with Bash
What sections of the SSP include detailed technical artifacts like IP inventories or vulnerability scans?
Open an interactive chat with Bash
ISC2 Governance, Risk and Compliance (CGRC)
Scope of the System
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .