Risk Management & Security Flashcards
7 cards from real CRM practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Risk Management & Security flashcards as text
Which of the following is the primary objective of a records disaster recovery plan (DRP)?
Answer: To restore critical records operations within defined recovery time objectives
A DRP defines procedures and recovery time objectives (RTOs) to restore essential records functions after a disruptive event.
An organization uses a records management vendor to store off-site backups. Which security practice is most important to verify in the vendor contract?
Answer: Right-to-audit clauses and security compliance certifications
Right-to-audit provisions and security certifications (e.g., ISO 27001, SOC 2) ensure the vendor maintains required security controls and allows verification.
Which federal law requires that agencies designate certain records as 'vital records' and maintain programs to protect them?
Answer: Federal Records Act
The Federal Records Act establishes the framework for federal records management, including vital records programs to ensure continuity of government operations.
During a records audit, an auditor finds that access logs for a sensitive records system have not been reviewed in six months. This finding most directly indicates a failure in which control type?
Answer: Detective control
Detective controls (like log reviews) identify incidents or unauthorized activity after they occur; failing to review logs means threats go undetected.
What is 'information classification' designed to accomplish in a records security program?
Answer: Establish consistent handling requirements based on the sensitivity and value of records
Information classification ensures records are handled, stored, transmitted, and destroyed according to their sensitivity level and business value.
A records manager is asked to evaluate the risk of storing Social Security numbers in an unencrypted flat-file database. The vulnerability in this scenario is:
Answer: The absence of encryption on a database containing sensitive personal identifiers
The vulnerability is the lack of encryption — a weakness in the technical control that could be exploited to expose sensitive PII.
Which of the following best describes 'residual risk' in records management?
Answer: The risk that remains after implementing risk treatment measures
Residual risk is the level of risk that persists after all planned security controls and risk treatments have been applied.