ISC2 Governance, Risk and Compliance (CGRC) Practice Question

Your agency's moderate-impact information system has just received an authorization to operate. The authorizing official reminds you that any significant system change-such as major configuration modifications-must automatically trigger a new assessment of affected controls. According to NIST SP 800-37 Revision 2 Task M-1, which RMF artifact is required to spell out those event-driven triggers and map them to the system's ongoing control-assessment schedule so external assessors can confirm compliance?

  • System Security Plan (SSP)

  • Authorization Decision Document (ATO letter)

  • System-level Continuous Monitoring Strategy (CM strategy)

  • Configuration Management Plan (CMP)

ISC2 Governance, Risk and Compliance (CGRC)
Selection and Approval of Framework, Security, and Privacy Controls
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot