← All CSC Flashcard Decks

Governance, Risk Management & Policy Development Flashcards

7 cards from real CSC practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Governance, Risk Management & Policy Development flashcards as text
  1. An organization's risk appetite statement says they will accept risks with residual risk scores below 10. A new system has a residual score of 8. What action should be taken?

    Answer: Accept the risk as it falls within the defined risk appetite

    Since the residual risk score of 8 falls below the acceptance threshold of 10, the risk aligns with the organization's stated risk appetite and should be accepted.

  2. Which concept describes an organization's willingness to tolerate risk in pursuit of its objectives?

    Answer: Risk appetite

    Risk appetite is the amount and type of risk an organization is willing to accept to achieve its goals.

  3. A third-party vendor will have access to sensitive customer data. From a governance perspective, what should be established BEFORE granting access?

    Answer: A formal vendor risk assessment and contractual data protection requirements

    Vendor risk assessments and contractual obligations ensure third parties meet the organization's security and compliance requirements before access is granted.

  4. Which framework introduced the concept of the 'Five Functions' — Identify, Protect, Detect, Respond, Recover — for cybersecurity risk management?

    Answer: NIST Cybersecurity Framework (CSF)

    The NIST Cybersecurity Framework (CSF) organizes cybersecurity activities into five core functions: Identify, Protect, Detect, Respond, and Recover.

  5. An organization wants to ensure its risk management activities are repeatable and consistent. What tool BEST supports this goal?

    Answer: A standardized risk management methodology with defined processes

    A standardized methodology with defined processes ensures consistency and repeatability across all risk management activities.

  6. Which element of a security policy MOST directly enables enforcement and accountability?

    Answer: Clearly stated consequences for non-compliance

    Defining consequences for non-compliance makes policies enforceable and holds individuals accountable for adhering to them.

  7. A security governance review finds that business units are making independent IT decisions without consulting security. This is BEST addressed by implementing which of the following?

    Answer: A formal IT governance committee with security representation

    A formal IT governance committee with security representation ensures that security considerations are integrated into all IT-related business decisions.