IT Governance and Cybersecurity Flashcards
7 cards from real GRC practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 IT Governance and Cybersecurity flashcards as text
A CISO presents a risk appetite statement to the board. What does this statement primarily define?
Answer: The level of risk the organization is willing to accept in pursuit of its objectives
Risk appetite defines the amount and type of risk an organization is willing to accept while pursuing its strategic goals.
Which cybersecurity governance model separates ownership of data from custody and use, assigning accountability to a named individual for each data set?
Answer: Data stewardship model
Data stewardship assigns named data owners accountable for data classification, protection, and lifecycle management across the organization.
Which ISO standard provides guidance specifically on information security governance for boards and senior executives?
Answer: ISO/IEC 27014
ISO/IEC 27014 provides guidance on concepts and principles for the governance of information security at the organizational level.
An organization uses a RACI matrix for its cybersecurity program. What does the 'A' in RACI represent?
Answer: Accountable — the person who owns the outcome and signs off
In a RACI matrix, 'Accountable' designates the single person who is ultimately answerable for the correct completion of a task or decision.
When implementing IT governance controls, what is the primary purpose of segregation of duties (SoD)?
Answer: To prevent fraud and errors by ensuring no single person controls all aspects of a critical process
Segregation of duties prevents conflicts of interest and reduces the risk of fraud or undetected errors by requiring multiple people to complete sensitive transactions.
A cybersecurity policy states that all employees must complete annual security awareness training. Which governance element does this policy represent?
Answer: Directive control
A directive control establishes rules or requirements that guide behavior, such as mandatory training policies.
Under the NIST Cybersecurity Framework, which function involves identifying assets, risks, and governance requirements?
Answer: Identify
The 'Identify' function establishes an organizational understanding of cybersecurity risks to systems, assets, data, and capabilities.