grc flashcards

0.0(0)
Studied by 0 people
call kaiCall Kai
Locked
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/69

encourage image

There's no tags or description

Looks like no tags are added yet.

Last updated 3:03 PM on 6/17/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

70 Terms

1
New cards

What are the 3 pillars of GRC?

Governance, Risk, and Compliance

2
New cards

What does Governance mean in GRC?

The rules, policies, roles, and accountability structures — who decides, who's responsible, and what the standards are

3
New cards

What does the Risk pillar mean in GRC?

Identifying what could go wrong, how likely it is, and how severe the impact would be

4
New cards

What does Compliance mean in GRC?

Proving you actually follow laws, regulations, and your own internal policies

5
New cards

What is a risk register?

The master record listing all identified risks, their scores, owners, and treatments

6
New cards

What is inherent risk?

The level of risk BEFORE any controls are applied

7
New cards

What is residual risk?

The level of risk REMAINING after controls are applied

8
New cards

What is risk appetite?

The amount of risk an organization is WILLING to accept to pursue its goals

9
New cards

What is risk tolerance?

The acceptable variation around the risk appetite (more specific and measurable)

10
New cards

What are the 4 risk treatment options?

Mitigate, Accept, Transfer, Avoid

11
New cards

What does it mean to Mitigate a risk?

Reduce the likelihood or impact by applying controls

12
New cards

What does it mean to Transfer a risk?

Shift it to a third party, e.g. via insurance or outsourcing

13
New cards

What is the formula for a risk score?

Likelihood x Impact

14
New cards

What is a control?

A safeguard that reduces risk (e.g. MFA, encryption, a policy)

15
New cards

What are the 3 control types?

Preventive, Detective, Corrective

16
New cards

Give an example of a preventive control

A firewall or MFA — it stops something from happening

17
New cards

Give an example of a detective control

Logs, monitoring, or alerts — it spots something that happened

18
New cards

Give an example of a corrective control

Backups/restore — it fixes things after an incident

19
New cards

What is a compensating control?

An alternative control used when the ideal control isn't feasible

20
New cards

What is a control owner?

The person accountable for ensuring a control works

21
New cards

What is evidence (an artifact) in GRC?

Proof that a control is working — screenshots, logs, policy docs

22
New cards

What is an audit finding?

A gap or deficiency identified by an auditor

23
New cards

What is remediation?

The act of fixing an audit finding or gap

24
New cards

What is a gap analysis?

Comparing current state against a required state to find deficiencies

25
New cards

What is the CIA triad?

Confidentiality, Integrity, Availability

26
New cards

What are the 6 NIST CSF 2.0 functions in order?

Govern, Identify, Protect, Detect, Respond, Recover

27
New cards

What is new in NIST CSF 2.0?

The Govern function was added as the overarching sixth function

28
New cards

What does the CSF Identify function cover?

Understanding your assets, data, systems, and risks

29
New cards

What does the CSF Protect function cover?

Safeguards: access control, training, data security, maintenance

30
New cards

What does the CSF Detect function cover?

Finding incidents through monitoring, anomalies, and alerts

31
New cards

What is the CSF structure hierarchy?

Functions > Categories > Subcategories

32
New cards

What are NIST CSF Tiers?

Maturity levels 1-4: Partial, Risk-Informed, Repeatable, Adaptive

33
New cards

What are NIST CSF Profiles?

Current vs Target state, used for gap analysis

34
New cards

What is NIST SP 800-53?

A catalog of 1,000+ security and privacy controls organized into ~20 families

35
New cards

Name 5 key NIST 800-53 control families

AC (Access Control), AU (Audit & Accountability), IA (Identification & Authentication), IR (Incident Response), RA (Risk Assessment)

36
New cards

What are the 800-53 baselines?

Low, Moderate, and High — based on system impact level

37
New cards

What are the 7 steps of the NIST RMF?

Prepare, Categorize, Select, Implement, Assess, Authorize, Monitor

38
New cards

What is an ATO in RMF?

Authority to Operate — leadership's formal acceptance of risk in the Authorize step

39
New cards

What does FIPS 199 do?

Categorizes a system's impact level (Low/Moderate/High) based on C, I, A

40
New cards

What is ISO 27001?

The international standard for an Information Security Management System (ISMS)

41
New cards

What is an ISMS?

Information Security Management System — a systematic, documented approach to managing security

42
New cards

What is a Statement of Applicability (SoA)?

An ISO 27001 document stating which controls apply and why

43
New cards

What are the 4 ISO 27001:2022 Annex A control themes?

Organizational, People, Physical, Technological

44
New cards

How many controls are in ISO 27001:2022 Annex A?

93 controls

45
New cards

Is ISO 27001 certifiable?

Yes — by an accredited external body (unlike NIST CSF, which is self-assessed)

46
New cards

What is ISO 31000?

A risk management methodology/framework (not certifiable)

47
New cards

What are the steps of the ISO 31000 risk process?

Establish context, Identify, Analyze, Evaluate, Treat, Monitor & review

48
New cards

What is SOC 2?

An attestation report from a CPA firm proving a company protects customer data

49
New cards

What are the 5 SOC 2 Trust Services Criteria?

Security, Availability, Processing Integrity, Confidentiality, Privacy

50
New cards

Which SOC 2 criterion is always required?

Security (the Common Criteria)

51
New cards

What is the difference between SOC 2 Type I and Type II?

Type I = controls designed properly at a point in time; Type II = controls operate effectively over a period (3-12 months)

52
New cards

Who does PCI-DSS apply to and what does it protect?

Anyone handling credit card data; protects cardholder data

53
New cards

Who does HIPAA apply to and what does it protect?

Healthcare orgs and their vendors; protects PHI (protected health information)

54
New cards

Who does GDPR apply to and what does it protect?

Anyone handling EU residents' data; protects personal data

55
New cards

What is GDPR's breach notification deadline?

72 hours

56
New cards

What is the CCPA/CPRA?

California's data privacy law, the US equivalent of GDPR

57
New cards

What is a control crosswalk?

A mapping of one control across multiple frameworks (CSF, ISO, 800-53, SOC 2)

58
New cards

What is a SIG questionnaire?

Standardized Information Gathering — a comprehensive industry-standard vendor security questionnaire

59
New cards

What is a CAIQ?

Consensus Assessments Initiative Questionnaire — a cloud vendor security questionnaire from the CSA

60
New cards

Why collect a vendor's SOC 2 report?

It lets you rely on their auditor's work instead of auditing them yourself

61
New cards

Name two security ratings tools

SecurityScorecard and BitSight

62
New cards

What are the steps of the vendor risk lifecycle?

Intake, Tiering, Due diligence, Risk scoring, Contract/SLA, Ongoing monitoring, Offboarding

63
New cards

What is the cloud shared responsibility model?

The provider secures the cloud; the customer secures what's in the cloud

64
New cards

What is CSPM?

Cloud Security Posture Management — tools that scan cloud configs for misconfigurations

65
New cards

Name a common cloud misconfiguration risk

A publicly exposed S3 storage bucket

66
New cards

What is ISO 42001?

The world's first AI management system standard — the 'ISO 27001 for AI'

67
New cards

What are the 4 functions of the NIST AI RMF?

Govern, Map, Measure, Manage

68
New cards

What is the EU AI Act?

Risk-based AI regulation tiering systems as unacceptable, high, limited, or minimal risk

69
New cards

What is a PBC list in an audit?

'Provided By Client' list — the evidence request checklist auditors send

70
New cards

What is the difference between NIST CSF and ISO 27001?

CSF is a flexible, self-assessed US risk framework; ISO 27001 is a certifiable international ISMS standard