โ† All GRC Flashcard Decks

IT Governance and Cybersecurity Flashcards

7 cards from real GRC practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 IT Governance and Cybersecurity flashcards as text
  1. A governance committee reviews an IT investment proposal. Which framework component ensures IT investments deliver value and align with business strategy?

    Answer: Value delivery in COBIT

    COBIT's value delivery component ensures IT investments are prioritized and managed to deliver optimal business value.

  2. Which cybersecurity governance concept ensures that the controls implemented are proportional to the risk they address?

    Answer: Proportionality of controls

    Proportionality of controls ensures resources spent on security measures are commensurate with the risk level, avoiding over- or under-investment.

  3. An organization must demonstrate cybersecurity compliance to a federal agency. Which US framework is most likely mandated for federal information systems?

    Answer: NIST RMF (Risk Management Framework)

    NIST RMF is the mandatory framework for federal agencies under FISMA to manage security and privacy risks for information systems.

  4. In IT governance, an organization establishes a steering committee. What is the primary role of this committee?

    Answer: Prioritize IT investments and align technology strategy with business goals

    An IT steering committee provides governance oversight by aligning IT strategy with business objectives and prioritizing major IT investments.

  5. Which cybersecurity governance document outlines acceptable and prohibited uses of organizational IT resources by employees?

    Answer: Acceptable Use Policy (AUP)

    An Acceptable Use Policy defines what employees may and may not do with organizational IT resources, setting behavioral expectations.

  6. A cybersecurity audit finds that access reviews are conducted only annually. Which governance concern does this primarily raise?

    Answer: Excessive access accumulation and privilege creep risk

    Annual access reviews allow privilege creep to accumulate over time, where users retain access rights beyond what their current role requires.

  7. Which GRC concept links control objectives directly to business risks and regulatory requirements to demonstrate coverage?

    Answer: Control mapping / compliance mapping

    Control mapping links specific controls to the risks and regulatory requirements they address, demonstrating coverage and identifying gaps.