GRC Principles and Models 4 — Questions and Answers
Question 1: Which framework introduced the concept of 'Capability Maturity Model' adapted for GRC programs to measure process improvement?
- COBIT 5
- CMMI (Correct answer)
- ITIL v4
- FAIR
Correct answer: CMMI
The Capability Maturity Model Integration (CMMI) provides a scale from Level 1 (Initial) to Level 5 (Optimizing) to measure the maturity of organizational processes including GRC.
Question 2: In the context of GRC, 'control self-assessment' (CSA) is best described as:
- An external auditor's evaluation of internal controls
- A process where management and staff evaluate their own controls' effectiveness (Correct answer)
- A regulatory examination of compliance programs
- A vendor's assessment of their customer's security posture
Correct answer: A process where management and staff evaluate their own controls' effectiveness
Control self-assessment involves process owners and employees evaluating the adequacy and effectiveness of controls in their own area of responsibility.
Question 3: Under the COBIT framework, which domain is primarily concerned with setting direction and aligning IT with business goals?
- Build, Acquire and Implement
- Deliver, Service and Support
- Evaluate, Direct and Monitor
- Align, Plan and Organize (Correct answer)
Correct answer: Align, Plan and Organize
The 'Align, Plan and Organize' (APO) domain in COBIT addresses how IT strategy and planning align with business objectives.
Question 4: The FAIR (Factor Analysis of Information Risk) model is distinctive because it:
- Provides a qualitative-only approach to risk assessment
- Quantifies information risk in financial terms (Correct answer)
- Focuses exclusively on physical security risks
- Is designed only for financial services organizations
Correct answer: Quantifies information risk in financial terms
FAIR is a quantitative risk analysis model that expresses information risk in monetary terms, enabling direct comparison with business costs and benefits.
Question 5: Which principle in governance theory holds that those who make decisions should be held answerable for the outcomes of those decisions?
- Transparency
- Accountability (Correct answer)
- Responsiveness
- Participation
Correct answer: Accountability
Accountability is the obligation of decision-makers to answer to stakeholders for their actions and the results those actions produce.
Question 6: A 'key risk indicator' (KRI) differs from a 'key performance indicator' (KPI) in that a KRI:
- Measures past performance results
- Signals potential future risk events before they occur (Correct answer)
- Tracks regulatory compliance status
- Measures employee productivity
Correct answer: Signals potential future risk events before they occur
KRIs are forward-looking metrics that provide early warning of increasing risk exposure, while KPIs typically measure historical performance.
Question 7: In GRC frameworks, 'continuous monitoring' is preferred over periodic assessments primarily because it:
- Reduces the cost of compliance by eliminating audits
- Provides near-real-time visibility into control effectiveness and risk posture (Correct answer)
- Shifts accountability from management to automated systems
- Satisfies all regulatory requirements without additional review
Correct answer: Provides near-real-time visibility into control effectiveness and risk posture
Continuous monitoring detects control failures and risk changes as they occur, rather than only at the point-in-time snapshot an annual assessment provides.
Which framework introduced the concept of 'Capability Maturity Model' adapted for GRC programs to measure process improvement?