← All GRC Flashcard Decks

Policy and Procedure Management Flashcards

7 cards from real GRC practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Policy and Procedure Management flashcards as text
  1. An employee in a foreign subsidiary claims a corporate security policy violates local labor law. What should the GRC team do?

    Answer: Consult legal counsel to determine whether a jurisdictional exception or policy modification is needed

    Legal counsel must evaluate whether local law requires policy adaptation to avoid regulatory violations in that jurisdiction.

  2. Which document type provides the 'why' behind security requirements and sets management intent?

    Answer: Policy

    Policies communicate management's intent and the organization's position on a topic without prescribing specific implementation steps.

  3. During an audit, the auditor requests evidence that the acceptable use policy was in effect 18 months ago. What is needed?

    Answer: An archived version of the policy as it existed 18 months ago

    Auditors assessing historical compliance need the exact policy version that was in effect during the period under review.

  4. What is the risk of setting policy review cycles longer than 3 years?

    Answer: Policies may become misaligned with evolving threats, regulations, and business changes

    Long review cycles increase the likelihood that policies will not reflect current threats, technologies, or regulatory requirements.

  5. A guidelines document says employees 'should' encrypt sensitive emails. What does this language indicate?

    Answer: Encryption is a recommended practice but not required

    The word 'should' indicates a recommendation rather than a mandatory control, distinguishing guidelines from standards and policies.

  6. Which of the following best supports policy adoption in a decentralized organization with multiple business units?

    Answer: Develop enterprise-wide policies with business unit-specific annexes or supplements

    A federated approach with enterprise core policies and business unit supplements balances consistency with operational flexibility.

  7. What is the significance of a 'policy effective date' separate from the approval date?

    Answer: It provides time for communication, training, and system changes before compliance is required

    An effective date after the approval date allows the organization to prepare employees and systems before enforcement begins.