ISC2 Governance, Risk and Compliance (CGRC) Practice Question
Your agency is deploying a shared analytics platform where the hosting division will implement and manage several technical safeguards, while individual mission owners remain accountable for data-level protections. To meet NIST RMF requirements for securing formal agreement on this split of control responsibilities before the System Security Plan is finalized, which document should you create and have all parties sign?
System Authorization Decision document issued by the Authorizing Official
Continuous Monitoring Strategy describing metrics and reporting frequency
Configuration Baseline Deviation Report for tracking non-standard settings
Memorandum of Agreement that delineates shared and individual control responsibilities
When security controls are divided among multiple stakeholders, NIST SP 800-37 Rev. 2 advises organizations to document the specific roles, responsibilities, and expected commitments in a formal agreement such as a Memorandum of Agreement (MOA) or Memorandum of Understanding (MOU) before the System Security Plan is approved. A System Authorization Decision only records the Authorizing Official's risk determination; a Continuous Monitoring Strategy outlines how controls will be monitored; and a Configuration Baseline Deviation Report simply catalogs departures from approved settings. None of those documents constitute the required inter-stakeholder agreement on control ownership.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is the purpose of a Memorandum of Agreement (MOA) in the NIST RMF process?
Open an interactive chat with Bash
How does the MOA differ from a System Authorization Decision document?
Open an interactive chat with Bash
Why is it important to secure formal agreements on control ownership before finalizing the System Security Plan?
Open an interactive chat with Bash
ISC2 Governance, Risk and Compliance (CGRC)
Selection and Approval of Framework, Security, and Privacy Controls
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .