ISC2 Governance, Risk and Compliance (CGRC) Practice Question
While finalizing the control-implementation strategy for a new cloud-based electronic health records system, the security manager must prove that every planned security and privacy control satisfies both NIST SP 800-53 and ISO/IEC 27001 requirements. Which action is the most effective initial step to demonstrate this alignment?
Create a comprehensive plan of action and milestones to address any residual control gaps identified during assessment.
Develop a detailed crosswalk matrix that maps each selected control to the equivalent requirements in both frameworks.
Submit the draft system security plan to the authorizing official for formal approval of the control set.
Initiate continuous monitoring to collect evidence that implemented controls are operating across both frameworks.
The first task in showing that selected controls meet the requirements of multiple frameworks is to build a control-mapping (crosswalk) matrix. By listing each planned control and explicitly tracing it to the corresponding requirements in NIST SP 800-53 and ISO/IEC 27001 (and any other applicable standards), the manager can verify coverage, find gaps early, and provide clear evidence to auditors and stakeholders. Continuous monitoring, POA&M creation, and submitting the system security plan are all important activities, but they occur after the foundational work of confirming that control selections actually map to the required compliance objectives. Without an upfront mapping, subsequent monitoring, remediation tracking, or plan approvals may overlook misalignments and require rework later.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
How does a crosswalk matrix help align controls with NIST SP 800-53 and ISO/IEC 27001?
Open an interactive chat with Bash
Can you explain what NIST SP 800-53 and ISO/IEC 27001 focus on in terms of controls?
Open an interactive chat with Bash
What are the most important steps to create a crosswalk matrix for compliance frameworks?
Open an interactive chat with Bash
ISC2 Governance, Risk and Compliance (CGRC)
Implementation of Security and Privacy Controls
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .