โ† All GRC Flashcard Decks

Governance Frameworks & Best Practices Flashcards

7 cards from real GRC practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Governance Frameworks & Best Practices flashcards as text
  1. Which component of the COSO ERM framework 2017 update reflects the integration of strategy-setting with enterprise risk management?

    Answer: Strategy and objective-setting

    The 2017 COSO ERM update emphasized 'Strategy and Objective-Setting' as the component linking ERM directly to organizational strategy.

  2. A governance framework requires that policies cascade through an organization. Which document type sits directly below a board-approved policy?

    Answer: Standard

    Standards define mandatory, specific requirements that support policies, while procedures describe how to implement standards.

  3. The OECD Principles of Corporate Governance emphasize 'equitable treatment of shareholders,' which specifically addresses:

    Answer: Ensuring all shareholders, including minorities, have equal voting rights

    Equitable treatment requires that minority and foreign shareholders receive the same protections and voting rights as majority shareholders.

  4. In IT governance, a 'tollgate' review is best described as:

    Answer: A formal checkpoint where a project must meet criteria before proceeding

    A tollgate review is a structured decision point where stakeholders evaluate whether a project meets predefined criteria before authorizing the next phase.

  5. Which ISO standard specifically provides guidance on governance of information security, acting as a companion to ISO/IEC 27001?

    Answer: ISO/IEC 27014

    ISO/IEC 27014 provides guidance on governance of information security for board-level and executive evaluation, direction, and monitoring.

  6. When a GRC framework refers to 'residual risk,' it means the risk that remains after:

    Answer: Control measures have been applied

    Residual risk is the level of risk remaining after controls and mitigating measures have been implemented.

  7. The King IV Report on Corporate Governance is principally applied in which country and is notable for which approach?

    Answer: South Africa; apply-and-explain principles-based approach

    King IV is a South African governance code using an 'apply and explain' approach, where organizations disclose how they apply each principle.