CyberVista Governance, Risk, and Compliance Questions and Answers — Questions and Answers
Question 1: An organization is conducting a risk assessment and uses descriptive ratings such as 'High,' 'Medium,' and 'Low' to evaluate the likelihood and impact of identified risks based on expert judgment and experience. What type of risk assessment is being performed?
- Quantitative
- Qualitative (Correct answer)
- Hybrid
- Ad-hoc
Correct answer: Qualitative
A qualitative risk assessment uses descriptive or categorical ratings (e.g., high, medium, low) to evaluate risks based on subjective judgment, experience, and context. This method is less precise than a quantitative assessment but is often quicker and easier to perform when numerical data is not available.
Question 2: Which of the following BEST describes the primary purpose of a Business Impact Analysis (BIA) within a GRC framework?
- To identify and catalog all organizational assets and their monetary value.
- To select and implement specific security controls to mitigate threats.
- To identify critical business functions and determine the potential effects of a disruption to those functions. (Correct answer)
- To assign roles and responsibilities for the incident response team.
Correct answer: To identify critical business functions and determine the potential effects of a disruption to those functions.
A Business Impact Analysis (BIA) is a systematic process to identify critical business functions and evaluate the potential effects of a disruption on them. The BIA helps determine recovery priorities, recovery time objectives (RTOs), and the resources required to maintain operational resilience, forming the foundation for business continuity planning.
Question 3: A global company is looking to implement a comprehensive framework that is primarily focused on IT governance and aligning IT processes with business goals to deliver value. Which of the following frameworks would be the MOST appropriate choice?
- ISO/IEC 27001
- NIST Cybersecurity Framework (CSF)
- COBIT (Control Objectives for Information and Related Technologies) (Correct answer)
- CIS Controls
Correct answer: COBIT (Control Objectives for Information and Related Technologies)
COBIT is a framework developed by ISACA specifically for the governance and management of enterprise IT. Its primary focus is on aligning IT with business objectives, ensuring that IT investments deliver real value, and managing IT-related risks. While other frameworks focus more on security controls (NIST, CIS) or establishing an ISMS (ISO 27001), COBIT is distinct in its business-driven governance approach.
Question 4: Within a cybersecurity governance structure, what is the hierarchical relationship between policies, standards, and procedures?
- Standards are high-level goals, which are implemented by policies and detailed in procedures.
- Procedures are high-level statements, which are supported by standards and enforced by policies.
- Policies are high-level statements of intent, supported by mandatory standards, which are implemented through step-by-step procedures.
- Standards and policies are interchangeable, while procedures describe the technology used. (Correct answer)
Correct answer: Standards and policies are interchangeable, while procedures describe the technology used.
The correct hierarchy is that Policies are high-level statements of management's intent. Standards provide mandatory, specific requirements to support the policies. Procedures are detailed, step-by-step instructions that document how to implement the standards and, by extension, the policies.
Question 5: A U.S.-based e-commerce company processes data for customers in California and the European Union. A key difference in their compliance obligations between CCPA and GDPR relates to the basis for processing personal data. Which statement accurately describes this difference?
- Both regulations require an 'opt-in' consent model before collecting any user data.
- CCPA requires a legal basis for processing, while GDPR allows processing by default.
- GDPR requires a specific legal basis (like consent) for processing, while CCPA operates on an 'opt-out' model. (Correct answer)
- Both regulations have identical requirements for data breach notifications, making consent models similar.
Correct answer: GDPR requires a specific legal basis (like consent) for processing, while CCPA operates on an 'opt-out' model.
A primary difference between the two regulations is their approach to consent. GDPR requires organizations to have one of six specific legal bases (e.g., explicit consent, contractual necessity) to process personal data, which is an 'opt-in' model. CCPA, on the other hand, allows for the collection and processing of data by default but requires giving consumers a clear option to 'opt-out' of the sale or sharing of their personal information.
Question 6: An organization has identified a risk to its data center from a potential long-term power outage. The organization decides to purchase a contract with a third-party provider for a fully equipped disaster recovery site. Which risk treatment strategy is being employed?
- Risk Acceptance
- Risk Avoidance
- Risk Mitigation
- Risk Transference (Correct answer)
Correct answer: Risk Transference
Risk transference (or transfer) involves shifting the impact of a risk to a third party. By contracting with a disaster recovery site provider, the organization is transferring the responsibility and financial burden of maintaining a secondary site, thereby sharing the risk of a data center outage.
An organization is conducting a risk assessment and uses descriptive ratings such as 'High,' 'Medium,' and 'Low' to evaluate the likelihood and impact of identified risks based on expert judgment and experience.
What type of risk assessment is being performed?