← All GRC Flashcard Decks

Mixed Deck — All GRC Topics Flashcards

100 cards from real GRC practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 20 Mixed Deck — All GRC Topics flashcards as text
  1. What is the primary purpose of a vendor risk tiering model?

    Answer: To allocate due diligence intensity based on the risk each vendor poses

    Risk tiering ensures that high-risk vendors receive more rigorous due diligence while low-risk vendors receive lighter-touch reviews, optimizing resources.

  2. The 'three lines of defense' model assigns internal audit to which line?

    Answer: Third line

    Internal audit is the third line of defense, providing independent assurance over the first (operations) and second (risk/compliance) lines.

  3. What is the role of auditing in internal controls?

    Answer: Assess and ensure control effectiveness

    Auditing plays a crucial role in internal controls by independently assessing whether these controls are designed and operating effectively. It helps identify weaknesses, non-compliance, or inefficiencies within the control system. By providing an objective evaluation, auditing ensures that controls are robust enough to mitigate risks and achieve organizational objectives.

  4. The principle of 'separation of duties' in GRC primarily serves to:

    Answer: Prevent any single individual from controlling all aspects of a critical process

    Separation of duties is a key internal control that distributes tasks across multiple people to reduce the risk of error or fraud.

  5. In IT governance, an organization establishes a steering committee. What is the primary role of this committee?

    Answer: Prioritize IT investments and align technology strategy with business goals

    An IT steering committee provides governance oversight by aligning IT strategy with business objectives and prioritizing major IT investments.

  6. Which provision of the Gramm-Leach-Bliley Act (GLBA) requires financial institutions to develop a written information security program?

    Answer: Safeguards Rule

    The GLBA Safeguards Rule requires financial institutions to implement a comprehensive written information security program to protect customer financial information.

  7. Anti-bribery and anti-corruption (ABAC) programs in U.S. companies are primarily governed by which federal law?

    Answer: The Foreign Corrupt Practices Act (FCPA)

    The FCPA prohibits U.S. companies and individuals from bribing foreign government officials and requires maintenance of accurate books and records and adequate internal controls.

  8. A policy owner role is BEST described as:

    Answer: The executive accountable for the policy's content, accuracy, and enforcement

    The policy owner is accountable for ensuring the policy remains accurate, current, and effectively implemented.

  9. What is the PRIMARY objective of an internal audit function according to the IIA Standards?

    Answer: Add value and improve the organization's operations through assurance and consulting

    The IIA defines internal audit's mission as enhancing and protecting organizational value through risk-based assurance, advice, and insight.

  10. What is a risk control measure?

    Answer: Mitigate the risk’s likelihood or impact

    A risk control measure is any action, policy, procedure, or device designed to reduce the probability of a risk occurring or lessen its negative impact if it does occur. These measures are implemented to bring risks to an acceptable level, protecting the organization's assets, operations, and objectives. Examples include security systems, internal policies, and training programs.

  11. Which compliance framework is specifically designed to secure controlled unclassified information (CUI) in non-federal systems and organizations?

    Answer: NIST SP 800-171

    NIST SP 800-171 provides security requirements for protecting CUI in nonfederal information systems, often required by defense contractors.

  12. Which GRC model concept refers to the organization's total exposure to risk before any controls or mitigation are applied?

    Answer: Inherent risk

    Inherent risk is the natural level of risk in a process or activity before management applies controls to reduce it.

  13. The California Consumer Privacy Act (CCPA) grants California residents the right to:

    Answer: Know what personal data is collected about them and request its deletion

    CCPA gives California residents rights including knowing what personal data businesses collect, the right to delete it, and the right to opt out of its sale.

  14. Under HIPAA, a Business Associate Agreement (BAA) is required when a third party does which of the following?

    Answer: Creates, receives, maintains, or transmits PHI on behalf of a covered entity

    A BAA is required whenever a third-party business associate creates, receives, maintains, or transmits PHI while performing services for a covered entity.

  15. During the TPRM lifecycle, which phase occurs *after* a vendor has been onboarded and is focused on continuously tracking their performance, security posture, and adherence to contractual obligations?

    Answer: Ongoing Monitoring

    Ongoing monitoring is the phase of the TPRM lifecycle that takes place after a vendor is onboarded. It involves continuously assessing the vendor to ensure they remain compliant and uphold the agreements established in the contract and to detect any new or emerging risks in real-time.

  16. Which risk treatment option introduces new risks as a direct result of applying the original treatment?

    Answer: Secondary risk

    Secondary risks are unintended new risks created by implementing a risk response plan.

  17. When developing a regulatory change management process, which of the following is a critical element to ensure its effectiveness?

    Answer: A mechanism for assigning clear ownership and accountability for implementing required changes.

    An effective regulatory change management process must go beyond just identifying changes; it must ensure that those changes are implemented and embedded into the business. Assigning clear ownership and accountability for specific regulatory requirements and the necessary changes is crucial for this to happen. Without clear ownership, action items can be missed, leading to non-compliance.

  18. Why is segregation of duties important in internal controls?

    Answer: Reduce fraud and errors

    Segregation of duties is important in internal controls because it significantly reduces the opportunities for fraud and errors. By distributing critical tasks among multiple individuals, it prevents any single person from having the ability to both commit and conceal dishonest acts. This separation creates a system of checks and balances, enhancing accountability and integrity within processes.

  19. A GRC analyst maps controls to specific risks to demonstrate coverage. This activity is known as:

    Answer: Control mapping

    Control mapping links individual security or compliance controls to the specific risks they address, helping identify gaps and redundancies.

  20. The FAIR (Factor Analysis of Information Risk) model is distinctive because it:

    Answer: Quantifies information risk in financial terms

    FAIR is a quantitative risk analysis model that expresses information risk in monetary terms, enabling direct comparison with business costs and benefits.