ISC2 Governance, Risk and Compliance (CGRC) Practice Question
While updating the System Security Plan for a moderate-impact information system that processes employee Social Security numbers, you need to demonstrate compliance with federal PII handling requirements. Which tailoring decision best satisfies the data minimization principle during control selection?
Configure audit log retention to keep all PII records for seven years to aid potential litigation.
Require AES-256 encryption for all databases that contain Social Security numbers at rest.
Implement a mandatory two-person approval workflow before any user can view Social Security number records.
Replace the stored Social Security number with a system-generated unique employee identifier unless a statute specifically requires the SSN.
The data minimization principle requires collecting, processing, and retaining only the least amount of personally identifiable information (PII) necessary to accomplish an authorized purpose. Replacing Social Security numbers with system-generated identifiers wherever possible directly reduces the amount of sensitive data held, aligning with NIST SP 800-53 Rev. 5 privacy control DM-1 and the minimization guidance in NIST SP 800-122. Encrypting data, extending retention periods, or adding additional access approvals improve confidentiality and access control, but they do not reduce the volume of PII collected or stored, so they do not fulfill the minimization requirement as effectively.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is NIST SP 800-53 Rev. 5?
Open an interactive chat with Bash
What does the data minimization principle entail?
Open an interactive chat with Bash
Why is replacing SSNs with unique identifiers recommended for compliance?
Open an interactive chat with Bash
ISC2 Governance, Risk and Compliance (CGRC)
Selection and Approval of Framework, Security, and Privacy Controls
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .