← All GRC Flashcard Decks

Risk Management & Mitigation Strategies Flashcards

7 cards from real GRC practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Risk Management & Mitigation Strategies flashcards as text
  1. Which key performance indicator (KPI) in risk management measures how quickly an organization can restore operations after a disruption?

    Answer: Recovery Time Objective (RTO)

    RTO defines the maximum acceptable length of time to restore a business function after an incident.

  2. A third-party vendor stores sensitive customer data on behalf of your organization. Which risk category does this primarily represent?

    Answer: Third-party/supply chain risk

    Risks arising from reliance on external vendors or partners are classified as third-party or supply chain risks.

  3. In the NIST Risk Management Framework (RMF), what is the correct order of the first three steps?

    Answer: Prepare → Categorize → Select

    NIST RMF begins with Prepare, then Categorize (the system), then Select (security controls), followed by Implement, Assess, Authorize, and Monitor.

  4. Which risk mitigation technique involves duplicating critical systems to ensure availability during a failure?

    Answer: Redundancy

    Redundancy reduces the risk of system failure by maintaining backup components or systems that can take over if the primary fails.

  5. An organization uses scenario analysis to evaluate risks. What is the primary benefit of this approach?

    Answer: It explores plausible future situations to understand potential impacts

    Scenario analysis helps organizations anticipate various possible futures and evaluate how they would respond, improving preparedness.

  6. Which type of risk arises from inadequate or failed internal processes, people, systems, or external events?

    Answer: Operational risk

    Operational risk, as defined by Basel II/III, stems from breakdowns in internal processes, human errors, system failures, or external events.

  7. What is the purpose of a risk owner in a GRC program?

    Answer: To be accountable for managing and monitoring a specific risk

    A risk owner is an individual assigned responsibility for ensuring that a specific risk is adequately identified, assessed, and treated.