Governance and Compliance Flashcards
7 cards from real CIAM practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Governance and Compliance flashcards as text
A company subject to SOX must ensure that financial system access controls are tested by:
Answer: An independent auditor as part of ICFR testing
SOX Section 404 requires management assessment and independent auditor testing of internal controls over financial reporting (ICFR), including access controls.
Which IAM governance activity involves analyzing existing access assignments to discover and define roles based on actual usage patterns?
Answer: Role mining
Role mining analyzes current user entitlements to identify natural groupings and patterns that can be formalized into roles for RBAC implementation.
An organization wants to demonstrate continuous compliance with access control requirements. Which approach best achieves this compared to point-in-time audits?
Answer: Implementing automated, real-time control monitoring with alerting
Automated real-time monitoring continuously validates that controls are in place and immediately flags violations, providing a stronger assurance posture than periodic reviews.
Under the EU AI Act's risk-based framework, which category of AI system would an automated identity verification system used for high-stakes decisions most likely fall into?
Answer: High risk
AI systems used for biometric identification or access decisions in high-stakes contexts are classified as high-risk under the EU AI Act and subject to strict requirements.
Which principle in the FAIR (Factor Analysis of Information Risk) model represents the probable frequency of a threat event occurring?
Answer: Threat event frequency
Threat Event Frequency (TEF) in the FAIR model quantifies how often a threat agent is likely to act against an asset over a given time period.
A governance board wants to reduce identity-related risk without increasing operational burden. Which IAM initiative best balances both goals?
Answer: Implementing risk-based access certification that focuses reviews on high-risk accounts
Risk-based certification focuses review effort on the highest-risk accounts and entitlements, reducing compliance burden while improving overall risk posture.
Which document formally defines the acceptable use, ownership, and enforcement responsibilities for IAM policies within an organization?
Answer: Identity governance charter
An identity governance charter establishes the mandate, scope, roles, and responsibilities for the IAM program, providing governance authority and accountability.