← All CRM Flashcard Decks

Risk Management & Security Flashcards

7 cards from real CRM practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Risk Management & Security flashcards as text
  1. Which type of risk assessment methodology assigns numeric values to the likelihood and impact of threats to calculate an overall risk score?

    Answer: Quantitative assessment

    Quantitative risk assessment uses numeric values and formulas (such as ALE = ARO × SLE) to produce measurable risk scores.

  2. A records manager discovers that classified contracts are stored in an unlocked filing cabinet in a shared workspace. This situation primarily represents which category of risk?

    Answer: Operational risk

    Operational risk arises from failures in internal processes, people, or physical controls, such as inadequate physical security for records.

  3. Under NIST SP 800-60, what is the primary purpose of information type categorization?

    Answer: To determine the appropriate security category for federal information systems

    NIST SP 800-60 maps information types to security categories (confidentiality, integrity, availability) to guide federal information system security.

  4. Which control is specifically designed to limit the number of employees who can access highly sensitive personnel records?

    Answer: Need-to-know access

    Need-to-know access restricts record access to only those individuals whose job functions require it, reducing unauthorized disclosure risk.

  5. A records security plan should address which of the following to protect records during a declared disaster?

    Answer: Vital records protection and off-site storage

    Vital records protection, including duplication and off-site storage, ensures critical records survive disasters and support business continuity.

  6. What is the recommended first step when an organization suspects a records-related data breach?

    Answer: Contain the breach and assess the scope before further action

    Incident response best practice requires containment and assessment of the breach scope before notifications or other remedial actions.

  7. Which document formally authorizes an organization's information security program and assigns high-level accountability to senior management?

    Answer: Information security policy

    An information security policy is a high-level management directive that establishes the program, assigns responsibility, and sets the tone for compliance.