ISC2 Governance, Risk and Compliance (CGRC) Practice Question
Your organization is planning to retire an on-premises customer-relationship management (CRM) system that stores regulated personal data. Before approving the decommissioning plan, the information system security officer (ISSO) must confirm that all legal, regulatory, and operational requirements have been addressed. Which of the following actions BEST satisfies the "review and confirm" step for system decommissioning under the Risk Management Framework?
Notify end users of the retirement date and publish instructions for migrating active records to the replacement platform.
Convene a documented review with the system owner, legal/compliance, records management, and privacy stakeholders to validate retention, sanitization, and reporting obligations before authorizing disposal.
Initiate secure media sanitization procedures for all storage devices to ensure that customer data cannot be recovered after shutdown.
Disable all user accounts associated with the CRM application and update the asset inventory to show the system as inactive.
Prior to shutting down or removing a system, the RMF decommissioning step requires a deliberate review with those who understand the organization's legal, regulatory, and business obligations. Facilitating a formal meeting with the system owner, legal/compliance counsel, records management, and privacy officers enables identification of statutory data-retention periods, e-discovery holds, contractual duties, and ongoing mission needs. Documenting the agreed-upon sanitization, archiving, and reporting activities demonstrates that the organization has validated requirements and secured management approval before executing technical disposal tasks. Simply erasing media, powering systems off, or notifying users may be necessary later, but none of those tasks by themselves confirms that all obligations have been analyzed and accepted by the appropriate authorities.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is the Risk Management Framework (RMF)?
Open an interactive chat with Bash
What is data sanitization, and why is it important in system decommissioning?
Open an interactive chat with Bash
Who are the key stakeholders involved in the system decommissioning review?
Open an interactive chat with Bash
ISC2 Governance, Risk and Compliance (CGRC)
Compliance Maintenance
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .