← All GRC Flashcard Decks

Risk Management & Mitigation Strategies Flashcards

7 cards from real GRC practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Risk Management & Mitigation Strategies flashcards as text
  1. Which document formally authorizes an information system to operate despite known risks?

    Answer: Authorization to Operate (ATO)

    An ATO is a formal decision by an authorizing official to accept the risk of operating a system based on the implemented security controls.

  2. A company discovers that a firewall misconfiguration has been present for six months. Which risk metric best measures how long the vulnerability was exposed?

    Answer: Mean Time to Detect (MTTD)

    MTTD measures the average time between when a vulnerability or incident occurs and when it is discovered.

  3. In risk management, 'threat modeling' is best described as:

    Answer: A structured process for identifying, enumerating, and prioritizing potential threats to a system

    Threat modeling proactively identifies threats, vulnerabilities, and countermeasures during design or assessment to improve security posture.

  4. Which risk response strategy is most appropriate when a risk has very low likelihood and very low impact?

    Answer: Accept

    Low-likelihood, low-impact risks are typically accepted because the cost of treating them outweighs the expected loss.

  5. A GRC analyst maps controls to specific risks to demonstrate coverage. This activity is known as:

    Answer: Control mapping

    Control mapping links individual security or compliance controls to the specific risks they address, helping identify gaps and redundancies.

  6. Which international standard provides a framework for information security risk management specifically?

    Answer: ISO 27005

    ISO 27005 provides guidelines for information security risk management and is designed to support implementation of ISO 27001.

  7. During a risk review, the team identifies that a mitigation control has reduced the likelihood of a risk but not its impact. What has changed?

    Answer: The residual risk profile has changed — lower likelihood, same impact

    Reducing likelihood while keeping impact constant lowers the overall residual risk score but does not eliminate the risk.