← All GRC Flashcard Decks

Enterprise Risk Management Frameworks Flashcards

7 cards from real GRC practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Enterprise Risk Management Frameworks flashcards as text
  1. Which of the following best describes a 'Key Risk Indicator' (KRI) in ERM?

    Answer: A forward-looking metric that signals increasing risk exposure

    KRIs are early-warning metrics that signal potential risk increases before a loss event occurs, enabling proactive management.

  2. In the NIST Cybersecurity Framework (CSF), which function focuses on limiting the impact of a cybersecurity incident?

    Answer: Respond

    The Respond function of NIST CSF focuses on containing the impact of a cybersecurity incident once it has been detected.

  3. A risk register typically contains all of the following EXCEPT:

    Answer: Employee performance evaluations

    Risk registers document risk details, ownership, likelihood, impact, and treatment plans — HR performance data is not a risk register component.

  4. What does 'risk velocity' refer to in enterprise risk management?

    Answer: The speed at which a risk could impact the organization if it materializes

    Risk velocity measures how quickly a risk could escalate from identification to impact, influencing how rapidly a response must be activated.

  5. Which framework component ensures that risk information flows up, down, and across the organization?

    Answer: Information and Communication

    The Information and Communication component ensures relevant risk data is captured and distributed to stakeholders at all organizational levels.

  6. An organization decides not to launch a new product line because the associated risks exceed its appetite. Which response strategy does this represent?

    Answer: Avoid

    Avoidance means not pursuing an activity or decision because the risk is deemed unacceptable relative to the potential reward.

  7. In the Three Lines of Defense model, which line is responsible for risk ownership and day-to-day control implementation?

    Answer: First line (operational management)

    The first line of defense — operational management — owns risks and is responsible for implementing and maintaining effective internal controls.