ISC2 Governance, Risk and Compliance (CGRC) Practice Question
Your organization's continuous monitoring program is currently aligned with federal privacy law. A newly enacted state statute broadens the definition of personal information and imposes shorter breach-notification timelines. To keep the monitoring program compliant, what should the compliance team do first when revising its monitoring strategy?
Immediately deploy additional data-loss-prevention rules to block transmission of state residents' data.
Map the new statutory requirements to the current control set to identify monitoring gaps.
Suspend collection of data from state residents until systems can be fully re-certified.
Advise senior leadership that monitoring costs will rise and request additional funding.
The logical first action is to perform a structured comparison-often called a gap analysis-between the new statutory requirements and the organization's existing security and privacy controls. Mapping each new legal obligation to current controls reveals where monitoring coverage is sufficient and where it must be enhanced. Rolling out technical changes, requesting budget, or halting data processing before completing this analysis risks wasting resources or interrupting operations without clear justification. A documented gap analysis provides the evidence base for any subsequent updates to tools, procedures, or budgets.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is a gap analysis in the context of governance, risk, and compliance?
Open an interactive chat with Bash
Why is mapping new statutory requirements to current controls important before implementing changes?
Open an interactive chat with Bash
What are the risks of not performing a gap analysis when modifying a compliance program?
Open an interactive chat with Bash
ISC2 Governance, Risk and Compliance (CGRC)
Compliance Maintenance
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .