Risk Management & Security Flashcards
7 cards from real CRM practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Risk Management & Security flashcards as text
Which concept describes the practice of keeping two separate individuals required to complete a sensitive records transaction, preventing any one person from acting alone?
Answer: Dual control
Dual control (two-person integrity) requires two authorized individuals to jointly perform a sensitive action, reducing insider threat and fraud risk.
An organization retains paper records in a storage facility. Which environmental control is most critical to prevent physical deterioration of paper documents?
Answer: Controlled temperature and humidity
Paper records degrade rapidly when exposed to high humidity, high temperatures, or fluctuating conditions, making climate control the top preservation priority.
When conducting a records risk assessment, 'threat' is best defined as:
Answer: Any circumstance or event with the potential to exploit a vulnerability
A threat is a potential source of harm (natural, human, or environmental) that could exploit a vulnerability in the records system.
Under the Privacy Act of 1974, federal agencies must do which of the following regarding records about individuals?
Answer: Allow individuals to access and request corrections to their own records
The Privacy Act grants individuals the right to access federal records about themselves and request amendments to inaccurate information.
A chain of custody document for evidentiary records must include which essential element?
Answer: A chronological log of every person who handled the records
Chain of custody requires a detailed log of everyone who accessed, transferred, or handled evidence to maintain its integrity and admissibility.
Which risk treatment option involves shifting potential financial losses from a records incident to a third party?
Answer: Risk transfer
Risk transfer moves the financial consequence of a risk to another party, typically through insurance or contractual agreements with service providers.
A records manager is implementing role-based access control (RBAC). What is the primary advantage of RBAC over assigning permissions individually to each user?
Answer: It simplifies administration by grouping users with similar job functions
RBAC groups users by job role and assigns permissions to roles, reducing the administrative burden of managing individual user permissions at scale.