1/16
Vocabulary flashcards covering the foundations of GRC, the four pillars of security, and the Third-Party Risk Management (TPRM) lifecycle and assessment tools.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
GRC
Governance, Risk, and Compliance; a strategic approach where governance acts as an enabler for business growth, rather than a blocker.
The Golden Rule of TPRM
"You can outsource the work, but you can never outsource the risk."
Pillar 1: Third-Party Risk Management (TPRM)
The discipline of assessing and monitoring external risk, based on the principle that security is only as strong as the weakest vendor.
Pillar 2: Security Awareness & Policy
A focus on training employees to be the first line of defense, noting that 90%+ of successful cyber attacks begin with a phishing email.
Pillar 3: Business Continuity (BC)
The practice of keeping the business running during a disruption, such as shifting operations to a secondary site during a pandemic.
Pillar 4: Disaster Recovery (DR)
The process of restoring IT systems and data after a failure, such as restoring from backups after a ransomware attack.
Security Compliance
The process of proving security to build trust with customers and regulators through internal controls, external audits, and following regulations.
Internal Controls
Rules an organization sets for itself, such as demanding that Passwords must be 12 chars.
External Audits
Verification by third parties to ensure an organization follows its own rules, such as a SOC 2 Type II audit.
Regulations
Laws that an organization is legally required to follow, such as GDPR or HIPAA.
Intake & Inherent Risk
The first stage of the TPRM Lifecycle which determines what data a vendor will access and assigns a risk level of High, Med, or Low.
Due Diligence
the second stage of the TPRM Lifecycle involving the review of SOC 2 reports and sending questionnaires like SIG or CAIQ.
Remediation
The third stage of the TPRM Lifecycle focused on fixing security gaps, such as requiring MFA, before a contract is signed.
Continuous Monitoring
The final stage of the TPRM Lifecycle involving real-time tracking of security breaches, financial health, and dark web chatter.
SIG (Standardized Information Gathering)
A comprehensive assessment tool created by Shared Assessments, available in Lite and Core versions, best used for general vendors like banks.
CAIQ (Consensus Assessments Initiative Questionnaire)
An assessment tool created by the Cloud Security Alliance (CSA) specifically for Cloud Providers (SaaS, IaaS) that maps to the Cloud Controls Matrix (CCM).
Risk Score Formula
Likelihood×Impact=Risk Score