ISC2 Governance, Risk and Compliance (CGRC) Practice Question
While updating a system security plan, you note a requirement stating that the Chief Information Security Officer must arrange an independent assessment of the information system each year and revise program-level policies based on the results. According to the NIST control classes, how should this requirement be categorized?
The requirement addresses how the organization manages risk through policy oversight and formal, periodic security assessments-activities that reside at the governance or program level rather than being performed by system operators or enforced through technology. Such policy, planning, and assessment activities are classic examples of management controls. Operational controls focus on day-to-day procedures executed by personnel, technical controls rely on automated mechanisms within hardware or software, and physical/environmental controls protect the facility and physical assets.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What are NIST control classes?
Open an interactive chat with Bash
Why is conducting an independent assessment considered a management control?
Open an interactive chat with Bash
How do operational controls differ from management controls?
Open an interactive chat with Bash
ISC2 Governance, Risk and Compliance (CGRC)
Implementation of Security and Privacy Controls
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .