1/69
Looks like no tags are added yet.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
What are the 3 pillars of GRC?
Governance, Risk, and Compliance
What does Governance mean in GRC?
The rules, policies, roles, and accountability structures — who decides, who's responsible, and what the standards are
What does the Risk pillar mean in GRC?
Identifying what could go wrong, how likely it is, and how severe the impact would be
What does Compliance mean in GRC?
Proving you actually follow laws, regulations, and your own internal policies
What is a risk register?
The master record listing all identified risks, their scores, owners, and treatments
What is inherent risk?
The level of risk BEFORE any controls are applied
What is residual risk?
The level of risk REMAINING after controls are applied
What is risk appetite?
The amount of risk an organization is WILLING to accept to pursue its goals
What is risk tolerance?
The acceptable variation around the risk appetite (more specific and measurable)
What are the 4 risk treatment options?
Mitigate, Accept, Transfer, Avoid
What does it mean to Mitigate a risk?
Reduce the likelihood or impact by applying controls
What does it mean to Transfer a risk?
Shift it to a third party, e.g. via insurance or outsourcing
What is the formula for a risk score?
Likelihood x Impact
What is a control?
A safeguard that reduces risk (e.g. MFA, encryption, a policy)
What are the 3 control types?
Preventive, Detective, Corrective
Give an example of a preventive control
A firewall or MFA — it stops something from happening
Give an example of a detective control
Logs, monitoring, or alerts — it spots something that happened
Give an example of a corrective control
Backups/restore — it fixes things after an incident
What is a compensating control?
An alternative control used when the ideal control isn't feasible
What is a control owner?
The person accountable for ensuring a control works
What is evidence (an artifact) in GRC?
Proof that a control is working — screenshots, logs, policy docs
What is an audit finding?
A gap or deficiency identified by an auditor
What is remediation?
The act of fixing an audit finding or gap
What is a gap analysis?
Comparing current state against a required state to find deficiencies
What is the CIA triad?
Confidentiality, Integrity, Availability
What are the 6 NIST CSF 2.0 functions in order?
Govern, Identify, Protect, Detect, Respond, Recover
What is new in NIST CSF 2.0?
The Govern function was added as the overarching sixth function
What does the CSF Identify function cover?
Understanding your assets, data, systems, and risks
What does the CSF Protect function cover?
Safeguards: access control, training, data security, maintenance
What does the CSF Detect function cover?
Finding incidents through monitoring, anomalies, and alerts
What is the CSF structure hierarchy?
Functions > Categories > Subcategories
What are NIST CSF Tiers?
Maturity levels 1-4: Partial, Risk-Informed, Repeatable, Adaptive
What are NIST CSF Profiles?
Current vs Target state, used for gap analysis
What is NIST SP 800-53?
A catalog of 1,000+ security and privacy controls organized into ~20 families
Name 5 key NIST 800-53 control families
AC (Access Control), AU (Audit & Accountability), IA (Identification & Authentication), IR (Incident Response), RA (Risk Assessment)
What are the 800-53 baselines?
Low, Moderate, and High — based on system impact level
What are the 7 steps of the NIST RMF?
Prepare, Categorize, Select, Implement, Assess, Authorize, Monitor
What is an ATO in RMF?
Authority to Operate — leadership's formal acceptance of risk in the Authorize step
What does FIPS 199 do?
Categorizes a system's impact level (Low/Moderate/High) based on C, I, A
What is ISO 27001?
The international standard for an Information Security Management System (ISMS)
What is an ISMS?
Information Security Management System — a systematic, documented approach to managing security
What is a Statement of Applicability (SoA)?
An ISO 27001 document stating which controls apply and why
What are the 4 ISO 27001:2022 Annex A control themes?
Organizational, People, Physical, Technological
How many controls are in ISO 27001:2022 Annex A?
93 controls
Is ISO 27001 certifiable?
Yes — by an accredited external body (unlike NIST CSF, which is self-assessed)
What is ISO 31000?
A risk management methodology/framework (not certifiable)
What are the steps of the ISO 31000 risk process?
Establish context, Identify, Analyze, Evaluate, Treat, Monitor & review
What is SOC 2?
An attestation report from a CPA firm proving a company protects customer data
What are the 5 SOC 2 Trust Services Criteria?
Security, Availability, Processing Integrity, Confidentiality, Privacy
Which SOC 2 criterion is always required?
Security (the Common Criteria)
What is the difference between SOC 2 Type I and Type II?
Type I = controls designed properly at a point in time; Type II = controls operate effectively over a period (3-12 months)
Who does PCI-DSS apply to and what does it protect?
Anyone handling credit card data; protects cardholder data
Who does HIPAA apply to and what does it protect?
Healthcare orgs and their vendors; protects PHI (protected health information)
Who does GDPR apply to and what does it protect?
Anyone handling EU residents' data; protects personal data
What is GDPR's breach notification deadline?
72 hours
What is the CCPA/CPRA?
California's data privacy law, the US equivalent of GDPR
What is a control crosswalk?
A mapping of one control across multiple frameworks (CSF, ISO, 800-53, SOC 2)
What is a SIG questionnaire?
Standardized Information Gathering — a comprehensive industry-standard vendor security questionnaire
What is a CAIQ?
Consensus Assessments Initiative Questionnaire — a cloud vendor security questionnaire from the CSA
Why collect a vendor's SOC 2 report?
It lets you rely on their auditor's work instead of auditing them yourself
Name two security ratings tools
SecurityScorecard and BitSight
What are the steps of the vendor risk lifecycle?
Intake, Tiering, Due diligence, Risk scoring, Contract/SLA, Ongoing monitoring, Offboarding
What is the cloud shared responsibility model?
The provider secures the cloud; the customer secures what's in the cloud
What is CSPM?
Cloud Security Posture Management — tools that scan cloud configs for misconfigurations
Name a common cloud misconfiguration risk
A publicly exposed S3 storage bucket
What is ISO 42001?
The world's first AI management system standard — the 'ISO 27001 for AI'
What are the 4 functions of the NIST AI RMF?
Govern, Map, Measure, Manage
What is the EU AI Act?
Risk-based AI regulation tiering systems as unacceptable, high, limited, or minimal risk
What is a PBC list in an audit?
'Provided By Client' list — the evidence request checklist auditors send
What is the difference between NIST CSF and ISO 27001?
CSF is a flexible, self-assessed US risk framework; ISO 27001 is a certifiable international ISMS standard