โ† All CCISO Flashcard Decks

Governance, Risk & Compliance Flashcards

7 cards from real CCISO practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Governance, Risk & Compliance flashcards as text
  1. Which element distinguishes a risk register from a risk assessment report?

    Answer: The risk register is a living document tracking risks over time; the report captures a point-in-time analysis

    A risk register is a continuously maintained inventory of identified risks, while a risk assessment report captures risk findings at a specific point in time.

  2. An organization wants to adopt a risk-based approach to compliance. Which concept BEST supports this?

    Answer: Prioritizing controls based on the likelihood and impact of associated risks

    A risk-based compliance approach focuses resources on controls that address the highest-likelihood and highest-impact risks first.

  3. Which type of policy establishes the organization's overall intention and direction for information security?

    Answer: Information Security Policy

    An Information Security Policy is the top-level document that sets the organization's strategic intent and commitment to protecting information assets.

  4. A third-party vendor will process sensitive customer data. Which contractual mechanism BEST ensures compliance with data protection requirements?

    Answer: Data Processing Agreement (DPA)

    A Data Processing Agreement legally defines how a third party must handle personal data and is required under regulations like GDPR.

  5. What is the key difference between qualitative and quantitative risk analysis?

    Answer: Qualitative uses descriptive categories like High/Medium/Low; quantitative uses numerical financial metrics like ALE

    Qualitative analysis rates risks using descriptive scales, while quantitative analysis expresses risk in monetary terms such as Annual Loss Expectancy (ALE).

  6. Which regulation primarily governs the handling of protected health information (PHI) by healthcare organizations in the United States?

    Answer: HIPAA

    HIPAA (Health Insurance Portability and Accountability Act) establishes privacy and security requirements for protected health information in the US.

  7. In the context of enterprise risk management, what does 'risk appetite' define?

    Answer: The amount of risk an organization is willing to accept in pursuit of its objectives

    Risk appetite represents the board-level decision about how much risk the organization is willing to tolerate while pursuing strategic goals.