Mastering Governance, Risk, and Compliance (GRC) Flashcards

0.0(0)
Studied by 0 people
call kaiCall Kai
Locked
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/16

flashcard set

Earn XP

Description and Tags

Vocabulary flashcards covering the foundations of GRC, the four pillars of security, and the Third-Party Risk Management (TPRM) lifecycle and assessment tools.

Last updated 4:48 AM on 8/3/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

17 Terms

1
New cards

GRC

Governance, Risk, and Compliance; a strategic approach where governance acts as an enabler for business growth, rather than a blocker.

2
New cards

The Golden Rule of TPRM

"You can outsource the work, but you can never outsource the risk."

3
New cards

Pillar 1: Third-Party Risk Management (TPRM)

The discipline of assessing and monitoring external risk, based on the principle that security is only as strong as the weakest vendor.

4
New cards

Pillar 2: Security Awareness & Policy

A focus on training employees to be the first line of defense, noting that 90%+90\%+ of successful cyber attacks begin with a phishing email.

5
New cards

Pillar 3: Business Continuity (BC)

The practice of keeping the business running during a disruption, such as shifting operations to a secondary site during a pandemic.

6
New cards

Pillar 4: Disaster Recovery (DR)

The process of restoring IT systems and data after a failure, such as restoring from backups after a ransomware attack.

7
New cards

Security Compliance

The process of proving security to build trust with customers and regulators through internal controls, external audits, and following regulations.

8
New cards

Internal Controls

Rules an organization sets for itself, such as demanding that Passwords must be 12 chars\text{Passwords must be 12 chars}.

9
New cards

External Audits

Verification by third parties to ensure an organization follows its own rules, such as a SOC 2 Type II audit.

10
New cards

Regulations

Laws that an organization is legally required to follow, such as GDPR or HIPAA.

11
New cards

Intake & Inherent Risk

The first stage of the TPRM Lifecycle which determines what data a vendor will access and assigns a risk level of High, Med, or Low.

12
New cards

Due Diligence

the second stage of the TPRM Lifecycle involving the review of SOC 2 reports and sending questionnaires like SIG or CAIQ.

13
New cards

Remediation

The third stage of the TPRM Lifecycle focused on fixing security gaps, such as requiring MFA, before a contract is signed.

14
New cards

Continuous Monitoring

The final stage of the TPRM Lifecycle involving real-time tracking of security breaches, financial health, and dark web chatter.

15
New cards

SIG (Standardized Information Gathering)

A comprehensive assessment tool created by Shared Assessments, available in Lite and Core versions, best used for general vendors like banks.

16
New cards

CAIQ (Consensus Assessments Initiative Questionnaire)

An assessment tool created by the Cloud Security Alliance (CSA) specifically for Cloud Providers (SaaS, IaaS) that maps to the Cloud Controls Matrix (CCM).

17
New cards

Risk Score Formula

Likelihood×Impact=Risk Score\text{Likelihood} \times \text{Impact} = \text{Risk Score}