CGRC Cheat Sheet 2026
The 30 highest-yield CGRC facts, distilled from real exam questions. Print it, save it as a PDF, or study it here — free, no sign-up.
125 questions
180 min time limit
70.00% to pass
- How does NIST SP 800-60 handle information types that are common across multiple government mission areas, such as financial management? → Volume I provides a common mission area taxonomy with suggested impact levels
- What is the role of 'tone at the top' in an effective compliance program? → Senior leadership visibly demonstrating commitment to ethical conduct and compliance
- In ISO 37000 (Governance of Organizations), which principle focuses on ensuring the organization creates value for stakeholders while managing trade-offs? → Value generation
- A vendor stores customer PII on behalf of your organization. Under GDPR, what role does this vendor hold? → Data Processor
- Which federal law in the United States specifically governs the collection of personal information from children under 13 years old? → COPPA
- An organization performs a threat analysis and finds that employees are the most frequent source of incidents. This category of threat source is called: → Insider threat
- What is a best practice in Certified Governance Risk and Compliance policy development? → A method or technique recognized as superior based on evidence and expert consensus
- What is a best practice in Certified Governance Risk and Compliance authorization process? → A method or technique recognized as superior based on evidence and expert consensus
- Which FedRAMP security assessment concept requires cloud service providers to maintain a continuously updated inventory of their security posture? → Continuous Monitoring (ConMon)
- What is the primary risk associated with conducting a penetration test without a signed rules of engagement (ROE) document? → The assessor may face legal liability for activities that would otherwise be authorized
- Which HIPAA rule specifically addresses the electronic exchange of health information and establishes national standards for electronic healthcare transactions? → Transactions and Code Sets Rule
- A healthcare organization must comply with both HIPAA and state privacy laws that are more stringent than HIPAA. What is the correct approach? → Comply with the more stringent state law requirements
- In Certified Governance Risk and Compliance, what role does continuing education play in governance principles? → To keep professionals current with evolving standards, technologies, and best practices
- What is the significance of a 'common control' in the RMF context? → A control whose implementation is inherited by multiple information systems
- Which NIST publication guides how to categorize federal information and information systems for security purposes? → FIPS 199 and NIST SP 800-60
- In Certified Governance Risk and Compliance, what is the primary function of strategic planning in audit management? → To set long-term goals and determine the best approach to achieve them
- Under NIST SP 800-122, what is the recommended approach for assessing privacy risk associated with PII? → Evaluate the likelihood of a PII breach and the impact on affected individuals
- Which framework provides specific guidance for managing information security risks in supply chains, particularly relevant to US federal agencies? → NIST SP 800-161
- Which type of assessment in Certified Governance Risk and Compliance compares an individual's performance to a predetermined standard? → Criterion-referenced assessment
- Which concept describes the practice of adjusting monitoring rigor based on a system's categorization level and data sensitivity? → Risk-based monitoring
- Which of the following best describes the concept of 'tone at the top' in governance? → Leadership's demonstrated commitment to ethical culture and compliance
- Which governance document formally defines the authority, responsibilities, and membership of a board committee? → Committee charter
- Which NIST publication provides guidance on conducting risk assessments as part of the RMF Prepare step? → NIST SP 800-30
- A risk register entry shows a threat with HIGH likelihood but LOW impact. How should this risk typically be prioritized? → Medium priority — monitor and apply cost-effective controls
- Under NIST SP 800-60, which federal government function is an example of a 'Management and Support' information type? → Human Resources Management
- An organization's governance framework should be reviewed and updated at minimum: → Periodically, at least annually
- Which compliance framework is MOST commonly used as a baseline for US federal government contractors handling controlled unclassified information (CUI)? → NIST SP 800-171
- Which practice ensures that vendor access to organizational systems is removed promptly when no longer needed? → Just-in-time provisioning and automated deprovisioning
- Under the NIST RMF, which step explicitly incorporates continuous monitoring activities into the system authorization lifecycle? → Step 6 – Monitor
- What is the primary objective of governance principles in Certified Governance Risk and Compliance? → To ensure competence and proficiency in core governance principles concepts
Turn these facts into recall:
Was this helpful?