โ† All GRC Flashcard Decks

Policy and Procedure Management Flashcards

7 cards from real GRC practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Policy and Procedure Management flashcards as text
  1. What distinguishes a procedure from a policy in the GRC policy hierarchy?

    Answer: Procedures provide step-by-step instructions for implementing policies

    Procedures are operational documents that describe the specific steps employees must take to comply with higher-level policies.

  2. An organization publishes a new data classification policy but employees continue using the old scheme. What is the most likely root cause?

    Answer: Insufficient communication and training on the new policy

    Without effective communication and training, employees lack awareness of policy changes and revert to familiar practices.

  3. Which governance body typically has final approval authority for enterprise-level security policies?

    Answer: The Board of Directors or executive leadership

    Enterprise-level policies reflect organizational risk appetite and require Board or executive approval to carry appropriate authority.

  4. A policy states that access reviews must occur 'regularly.' Why is this language problematic?

    Answer: Vague language cannot be consistently audited or enforced

    Vague terms like 'regularly' are not measurable, making it impossible to verify compliance or hold anyone accountable.

  5. When should a policy undergo an unscheduled review?

    Answer: After a significant security incident, regulatory change, or major business change

    Trigger-based reviews ensure policies remain relevant when significant events occur between scheduled review cycles.

  6. What role does a policy management tool (software) play in a mature GRC program?

    Answer: It centralizes policy storage, version control, workflow, and attestation tracking

    Policy management tools provide a single source of truth and automate lifecycle tasks like review reminders, approvals, and acknowledgment tracking.

  7. Which principle ensures that a policy is enforceable across the organization?

    Answer: Senior management must visibly support and comply with the policy

    Management commitment and visible compliance signal that the policy applies equally to all levels, reinforcing its authority.