GRC Policy and Procedure Management 2 — Questions and Answers
Question 1: Which element is most critical when establishing a policy exception process?
- Automatic approval after 30 days
- Documentation of risk acceptance and compensating controls (Correct answer)
- Exception requests submitted only by executives
- Exceptions granted permanently without review
Correct answer: Documentation of risk acceptance and compensating controls
A sound exception process requires documenting the risk being accepted and any compensating controls that reduce that risk.
Question 2: What is the primary purpose of a policy attestation process?
- To punish employees who violate policies
- To confirm that employees have read and understood policies (Correct answer)
- To replace policy training programs
- To automate policy enforcement
Correct answer: To confirm that employees have read and understood policies
Attestation formally confirms that employees have acknowledged and understood applicable policies, creating accountability.
Question 3: A company's information security policy conflicts with a newly enacted state privacy regulation. What should happen first?
- Continue following the existing policy until it expires
- Immediately suspend the conflicting policy sections
- Conduct a gap analysis to identify required policy changes (Correct answer)
- Delegate the conflict resolution to IT department
Correct answer: Conduct a gap analysis to identify required policy changes
A gap analysis identifies exactly where the policy conflicts with the regulation so targeted updates can be made.
Question 4: Which of the following best describes a 'standard' in GRC context?
- A high-level statement of management intent
- A specific mandatory requirement supporting a policy (Correct answer)
- A recommended optional practice
- A legal requirement from a regulatory body
Correct answer: A specific mandatory requirement supporting a policy
Standards are mandatory, specific requirements that operationalize policies and define minimum acceptable levels of compliance.
Question 5: During policy review, stakeholders disagree on the acceptable use of personal devices for work email. What is the best next step?
- The CISO decides unilaterally and publishes the policy
- Conduct a risk assessment to inform the decision (Correct answer)
- Delay the policy until consensus is naturally reached
- Adopt the most restrictive option without analysis
Correct answer: Conduct a risk assessment to inform the decision
A risk assessment provides objective data on threats, vulnerabilities, and impacts to support informed stakeholder decision-making.
Question 6: What is the recommended retention period consideration for superseded policy versions?
- They should be immediately deleted to avoid confusion
- Retain them according to the records retention schedule for audit and legal purposes (Correct answer)
- Keep only the most recent two versions
- Retention is optional and at department discretion
Correct answer: Retain them according to the records retention schedule for audit and legal purposes
Superseded policy versions may be needed to demonstrate compliance during audits covering historical periods or for litigation.
Question 7: Which metric best measures the effectiveness of a policy management program?
- Total number of policies published
- Policy exception request volume only
- Percentage of employees completing annual policy acknowledgment (Correct answer)
- Number of policy documents in the repository
Correct answer: Percentage of employees completing annual policy acknowledgment
Acknowledgment rates directly measure whether employees are engaging with policies, which is a leading indicator of compliance.
Which element is most critical when establishing a policy exception process?