GRC Cheat Sheet 2026
The 30 highest-yield GRC facts, distilled from real exam questions. Print it, save it as a PDF, or study it here — free, no sign-up.
100 questions
120 min time limit
75% to pass
- An organization publishes a new data classification policy but employees continue using the old scheme. What is the most likely root cause? → Insufficient communication and training on the new policy
- The ultimate goal of implementing an integrated GRC capability, as defined by OCEG, is to achieve: → Principled Performance
- Which type of risk arises from inadequate or failed internal processes, people, systems, or external events? → Operational risk
- The COSO Internal Control — Integrated Framework identifies five components. Which component addresses the 'tone at the top' concept? → Control Environment
- Which quantitative technique uses repeated random sampling to model the probability distribution of risk outcomes? → Monte Carlo simulation
- An organization separates the duties of transaction authorization, recording, and custody of assets. This is an example of: → Segregation of duties
- The NIST Privacy Framework's 'Communicate-P' function focuses on: → Increasing awareness of how privacy values are implemented in policies and practices
- A firm's BIA reveals that its order-processing system must be restored within 4 hours. This figure represents the: → RTO
- Under the Payment Card Industry Data Security Standard (PCI DSS), what is the minimum password length required for system access? → 12 characters
- Under the NIST Cybersecurity Framework, which function involves identifying assets, risks, and governance requirements? → Identify
- In GRC, what does 'inherent risk' refer to? → The risk that exists before any controls or mitigating actions are implemented
- Which term describes the risk that remains after all controls and mitigation strategies have been applied? → Residual risk
- How can organizations measure the effectiveness of their GRC programs? → Track KPIs and assess outcomes
- The concept of 'privacy by design' in regulatory compliance requires that privacy protections be integrated at which stage of system development? → From the earliest design phase onward
- What is the role of internal controls in governance? → Ensure effective operations and compliance
- Which risk response strategy is most appropriate when a risk has very low likelihood and very low impact? → Accept
- An organization sets its RPO at zero for financial transaction data. What technology best supports this requirement? → Synchronous real-time replication
- During an audit, the auditor requests evidence that the acceptable use policy was in effect 18 months ago. What is needed? → An archived version of the policy as it existed 18 months ago
- During a risk review, the team identifies that a mitigation control has reduced the likelihood of a risk but not its impact. What has changed? → The residual risk profile has changed — lower likelihood, same impact
- A company discovers that a firewall misconfiguration has been present for six months. Which risk metric best measures how long the vulnerability was exposed? → Mean Time to Detect (MTTD)
- Which governance concept describes the board's responsibility to ensure the organization acts in the long-term interests of shareholders and other stakeholders? → Agency theory
- Under the Children's Online Privacy Protection Act (COPPA), parental consent is required before collecting personal information from children under what age? → 13
- Which risk identification method involves structured interviews and workshops with business stakeholders to surface risks from those closest to the processes? → Facilitated risk workshops and interviews
- A risk register typically contains all of the following EXCEPT: → Employee performance evaluations
- What is a best practice in implementing governance frameworks? → Involve key stakeholders
- Which ISO standard specifically provides guidance on governance of information security, acting as a companion to ISO/IEC 27001? → ISO/IEC 27014
- In the context of internal auditing, what does 'independence' mean? → The internal audit function is free from conditions that threaten objectivity
- A governance committee reviews an IT investment proposal. Which framework component ensures IT investments deliver value and align with business strategy? → Value delivery in COBIT
- A governance framework requires that policies cascade through an organization. Which document type sits directly below a board-approved policy? → Standard
- Which metric is MOST useful for measuring how quickly an organization identifies and responds to vendor-related security incidents? → Mean Time to Detect and Respond (MTTR/MTTD) for vendor incidents
Turn these facts into recall:
Was this helpful?