← All CIAM Flashcard Decks

Governance and Compliance Flashcards

7 cards from real CIAM practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Governance and Compliance flashcards as text
  1. Which governance metric measures the percentage of user accounts that have completed a scheduled access review within the required timeframe?

    Answer: Certification completion rate

    Certification completion rate tracks what portion of accounts were reviewed and attested (or revoked) within the mandated review window.

  2. An IAM policy exception process should require which of the following before granting a temporary deviation from policy?

    Answer: Documented business justification, risk acceptance, and a defined expiration date

    A sound exception process requires documented justification, formal risk acceptance by an appropriate owner, and an expiration so exceptions do not become permanent.

  3. Which ISO standard specifically addresses information security management systems and is commonly used as an IAM governance framework reference?

    Answer: ISO 27001

    ISO 27001 specifies requirements for establishing, implementing, and maintaining an information security management system, including access control objectives.

  4. A 'ghost account' in IAM governance terminology refers to:

    Answer: An active account belonging to a user who no longer exists in the HR system

    Ghost (or orphan) accounts are active user accounts that remain in the system after the associated employee has left, posing a significant security and compliance risk.

  5. Which regulatory framework requires financial institutions to implement a written information security program covering administrative, technical, and physical safeguards?

    Answer: GLBA Safeguards Rule

    The GLBA Safeguards Rule requires financial institutions to develop, implement, and maintain a comprehensive written information security program.

  6. During an IAM maturity assessment, 'ad hoc and reactive' access management describes which maturity level?

    Answer: Level 1 – Initial

    Maturity Level 1 (Initial) is characterized by ad hoc, reactive, and undocumented processes with no consistent methodology.

  7. Which control provides assurance that access granted to a user matches what was formally approved in the provisioning request?

    Answer: Provisioning reconciliation

    Provisioning reconciliation compares what was approved in access requests against what was actually granted in target systems, identifying discrepancies.