GRC IT Governance and Cybersecurity 4 — Questions and Answers
Question 1: A governance committee reviews an IT investment proposal. Which framework component ensures IT investments deliver value and align with business strategy?
- Value delivery in COBIT (Correct answer)
- Risk response in COSO ERM
- Incident response in NIST
- Control testing in SOC 2
Correct answer: Value delivery in COBIT
COBIT's value delivery component ensures IT investments are prioritized and managed to deliver optimal business value.
Question 2: Which cybersecurity governance concept ensures that the controls implemented are proportional to the risk they address?
- Proportionality of controls (Correct answer)
- Defense in depth
- Least privilege
- Due diligence
Correct answer: Proportionality of controls
Proportionality of controls ensures resources spent on security measures are commensurate with the risk level, avoiding over- or under-investment.
Question 3: An organization must demonstrate cybersecurity compliance to a federal agency. Which US framework is most likely mandated for federal information systems?
- NIST RMF (Risk Management Framework) (Correct answer)
- CIS Controls
- SOC 2 Type II
- PCI DSS
Correct answer: NIST RMF (Risk Management Framework)
NIST RMF is the mandatory framework for federal agencies under FISMA to manage security and privacy risks for information systems.
Question 4: In IT governance, an organization establishes a steering committee. What is the primary role of this committee?
- Prioritize IT investments and align technology strategy with business goals (Correct answer)
- Configure and manage network security devices
- Conduct penetration tests on critical systems
- Develop detailed security policies and procedures
Correct answer: Prioritize IT investments and align technology strategy with business goals
An IT steering committee provides governance oversight by aligning IT strategy with business objectives and prioritizing major IT investments.
Question 5: Which cybersecurity governance document outlines acceptable and prohibited uses of organizational IT resources by employees?
- Acceptable Use Policy (AUP) (Correct answer)
- Incident Response Plan (IRP)
- Disaster Recovery Plan (DRP)
- System Security Plan (SSP)
Correct answer: Acceptable Use Policy (AUP)
An Acceptable Use Policy defines what employees may and may not do with organizational IT resources, setting behavioral expectations.
Question 6: A cybersecurity audit finds that access reviews are conducted only annually. Which governance concern does this primarily raise?
- Excessive access accumulation and privilege creep risk (Correct answer)
- Insufficient encryption of data at rest
- Lack of network segmentation controls
- Inadequate patch management processes
Correct answer: Excessive access accumulation and privilege creep risk
Annual access reviews allow privilege creep to accumulate over time, where users retain access rights beyond what their current role requires.
Question 7: Which GRC concept links control objectives directly to business risks and regulatory requirements to demonstrate coverage?
- Control mapping / compliance mapping (Correct answer)
- Gap analysis
- Business impact analysis
- Threat modeling
Correct answer: Control mapping / compliance mapping
Control mapping links specific controls to the risks and regulatory requirements they address, demonstrating coverage and identifying gaps.
A governance committee reviews an IT investment proposal.
Which framework component ensures IT investments deliver value and align with business strategy?