CGRC Study Guide 2026
Everything you need to pass the CGRC exam in one place: the exam format, every topic to study, real practice questions with explanations, flashcards, and full-length practice tests. Free, no sign-up needed.
📋 CGRC Exam Format at a Glance
📚 CGRC Topics to Study (89)
✍️ Sample CGRC Questions & Answers
1. The 'policy owner' role is PRIMARILY responsible for:
The policy owner is accountable for keeping the policy accurate, relevant, and enforced within their area of responsibility.
2. Which activity marks the formal beginning of the Authorize step in the NIST RMF lifecycle?
The Authorize step formally begins when the complete authorization package (SSP, SAR, POA&M) is submitted to the Authorizing Official for review.
3. What is the key difference between an Authorization to Operate (ATO) and an Authorization to Use (ATU)?
An Authorization to Use (ATU) allows an organization to use and rely on a system or service operated by another organization rather than operating it themselves.
4. An employee reports a potential compliance violation through the organization's hotline. Under best practices, what should happen FIRST?
Best practice requires confirming receipt, protecting the reporter from retaliation, and conducting a preliminary review before any other action.
5. An acceptable use policy (AUP) MOST commonly governs:
AUPs define acceptable and unacceptable use of organizational technology resources such as computers, networks, email, and internet access.
6. In the NIST RMF, information system categorization is which step of the framework?
Categorize is Step 2 of the NIST RMF, occurring after the Prepare step and before the Select step.