ISC2 Governance, Risk and Compliance (CGRC) Practice Question
Your agency's baseline requires full-disk encryption on every laptop that processes personally identifiable information (PII). Several legacy laptops lack the hardware needed for FDE and will not be replaced until next year. To satisfy the requirement with a compensating control that offers equivalent protection in the interim, which action is MOST appropriate?
Have employees sign a statement accepting personal responsibility if PII is exposed from the legacy laptops.
Allow PII only on organization-issued USB drives that provide hardware encryption and block local storage of PII on the legacy laptops.
Require users to set strong BIOS passwords on the affected laptops before each use.
Increase annual security-awareness training to remind users never to leave laptops unattended in public places.
A compensating control must deliver protection comparable to the original requirement. Full-disk encryption guards all data on the laptop if the device is lost or stolen. Preventing users from storing PII on the un-encryptable internal drives and mandating that any PII be kept only on government-issued USB devices that use approved hardware encryption preserves confidentiality even if the laptop is compromised, meeting the intent of the original control. While user training, BIOS passwords, or signed acknowledgements add some value, they do not offer protection equivalent to full-disk encryption because they neither encrypt the data nor reliably prevent unauthorized access if the laptop is lost.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is full-disk encryption (FDE) and how does it protect data?
Open an interactive chat with Bash
What are compensating controls and how do they work in cybersecurity?
Open an interactive chat with Bash
Why is hardware encryption preferred over other encryption methods for storing sensitive data?
Open an interactive chat with Bash
ISC2 Governance, Risk and Compliance (CGRC)
Implementation of Security and Privacy Controls
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .