CGRC Cheat Sheet 2026

The 30 highest-yield CGRC facts, distilled from real exam questions. Print it, save it as a PDF, or study it here — free, no sign-up.

125 questions
180 min time limit
70.00% to pass
  1. How does NIST SP 800-60 handle information types that are common across multiple government mission areas, such as financial management? Volume I provides a common mission area taxonomy with suggested impact levels
  2. What is the role of 'tone at the top' in an effective compliance program? Senior leadership visibly demonstrating commitment to ethical conduct and compliance
  3. In ISO 37000 (Governance of Organizations), which principle focuses on ensuring the organization creates value for stakeholders while managing trade-offs? Value generation
  4. A vendor stores customer PII on behalf of your organization. Under GDPR, what role does this vendor hold? Data Processor
  5. Which federal law in the United States specifically governs the collection of personal information from children under 13 years old? COPPA
  6. An organization performs a threat analysis and finds that employees are the most frequent source of incidents. This category of threat source is called: Insider threat
  7. What is a best practice in Certified Governance Risk and Compliance policy development? A method or technique recognized as superior based on evidence and expert consensus
  8. What is a best practice in Certified Governance Risk and Compliance authorization process? A method or technique recognized as superior based on evidence and expert consensus
  9. Which FedRAMP security assessment concept requires cloud service providers to maintain a continuously updated inventory of their security posture? Continuous Monitoring (ConMon)
  10. What is the primary risk associated with conducting a penetration test without a signed rules of engagement (ROE) document? The assessor may face legal liability for activities that would otherwise be authorized
  11. Which HIPAA rule specifically addresses the electronic exchange of health information and establishes national standards for electronic healthcare transactions? Transactions and Code Sets Rule
  12. A healthcare organization must comply with both HIPAA and state privacy laws that are more stringent than HIPAA. What is the correct approach? Comply with the more stringent state law requirements
  13. In Certified Governance Risk and Compliance, what role does continuing education play in governance principles? To keep professionals current with evolving standards, technologies, and best practices
  14. What is the significance of a 'common control' in the RMF context? A control whose implementation is inherited by multiple information systems
  15. Which NIST publication guides how to categorize federal information and information systems for security purposes? FIPS 199 and NIST SP 800-60
  16. In Certified Governance Risk and Compliance, what is the primary function of strategic planning in audit management? To set long-term goals and determine the best approach to achieve them
  17. Under NIST SP 800-122, what is the recommended approach for assessing privacy risk associated with PII? Evaluate the likelihood of a PII breach and the impact on affected individuals
  18. Which framework provides specific guidance for managing information security risks in supply chains, particularly relevant to US federal agencies? NIST SP 800-161
  19. Which type of assessment in Certified Governance Risk and Compliance compares an individual's performance to a predetermined standard? Criterion-referenced assessment
  20. Which concept describes the practice of adjusting monitoring rigor based on a system's categorization level and data sensitivity? Risk-based monitoring
  21. Which of the following best describes the concept of 'tone at the top' in governance? Leadership's demonstrated commitment to ethical culture and compliance
  22. Which governance document formally defines the authority, responsibilities, and membership of a board committee? Committee charter
  23. Which NIST publication provides guidance on conducting risk assessments as part of the RMF Prepare step? NIST SP 800-30
  24. A risk register entry shows a threat with HIGH likelihood but LOW impact. How should this risk typically be prioritized? Medium priority — monitor and apply cost-effective controls
  25. Under NIST SP 800-60, which federal government function is an example of a 'Management and Support' information type? Human Resources Management
  26. An organization's governance framework should be reviewed and updated at minimum: Periodically, at least annually
  27. Which compliance framework is MOST commonly used as a baseline for US federal government contractors handling controlled unclassified information (CUI)? NIST SP 800-171
  28. Which practice ensures that vendor access to organizational systems is removed promptly when no longer needed? Just-in-time provisioning and automated deprovisioning
  29. Under the NIST RMF, which step explicitly incorporates continuous monitoring activities into the system authorization lifecycle? Step 6 – Monitor
  30. What is the primary objective of governance principles in Certified Governance Risk and Compliance? To ensure competence and proficiency in core governance principles concepts
Turn these facts into recall:
Was this helpful?