ISC2 Governance, Risk and Compliance (CGRC) Practice Question
While updating the security control implementation section of a system security plan for a newly deployed customer-facing portal, you must show that each safeguard aligns with the portal's defined boundaries, business purpose, and accepted residual risk. Which documentation element best satisfies this requirement?
A table of all software patch identifiers and installation dates for components supporting the portal
Contact information for external service providers responsible for maintaining the portal's security devices
A catalog of industry frameworks (e.g., ISO 27001, CIS, COBIT) reviewed during control selection
A narrative mapping every implemented control to the business process it protects and noting residual risk formally accepted by the authorizing official
The most direct way to show that implemented controls fit the system's purpose, scope, and risk profile is to describe how each control protects specific mission or business processes and to record any residual risk that remains after the control is in place, including the authorizing official's acceptance. This narrative links the control to the organization's objectives and risk appetite. Listing technical details, vendor contacts, or generic regulatory references may be useful for operations or compliance mapping, but they do not, by themselves, demonstrate how the chosen controls address the system's unique context and residual risks.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is residual risk in risk management?
Open an interactive chat with Bash
How does a narrative mapping enhance security documentation?
Open an interactive chat with Bash
What role does the authorizing official play in risk acceptance?
Open an interactive chat with Bash
ISC2 Governance, Risk and Compliance (CGRC)
Implementation of Security and Privacy Controls
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .