ISC2 Governance, Risk and Compliance (CGRC) Practice Question
While preparing the strategy to deploy new security controls, the project team has already assigned control owners, defined success metrics, and produced a high-level schedule. Which additional element must be completed to make the implementation strategy fully comprehensive?
Create detailed unit test scripts for each implemented control
Define a change-freeze window to reduce deployment conflicts
Identify compensating controls for inherited system risks
Allocate and document budget for tools, licenses, and labor costs
A complete implementation strategy addresses four key planning components: resourcing (who will perform the work), timeline (when tasks will be executed), effectiveness (how success will be measured), and funding (how the effort will be paid for). In the scenario, resourcing (control owners), effectiveness (success metrics), and timeline (schedule) are already covered, leaving funding unaddressed. Securing and documenting the budget-including costs for tools, licenses, labor, and support-finalizes the plan. Identifying compensating controls is only necessary if baseline controls cannot be implemented, which has not been stated here. Defining a change-freeze window and creating unit-test scripts are useful deployment or testing activities but are not among the four core planning components required for the initial implementation strategy.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What are compensating controls?
Open an interactive chat with Bash
Why is documenting budgets critical for implementation strategies?
Open an interactive chat with Bash
What is the purpose of success metrics in security control implementation?
Open an interactive chat with Bash
ISC2 Governance, Risk and Compliance (CGRC)
Implementation of Security and Privacy Controls
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .