Governance, Risk & Compliance Flashcards
7 cards from real CCISO practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Governance, Risk & Compliance flashcards as text
Which of the following BEST describes the concept of 'control risk' in an audit context?
Answer: The risk that a misstatement will not be prevented or detected by internal controls
Control risk is the probability that an organization's internal controls will fail to prevent or detect a material misstatement or security issue.
What is the MAIN purpose of a Business Impact Analysis (BIA) in governance and continuity planning?
Answer: To determine recovery time objectives and the criticality of business functions
A BIA identifies critical business functions, assesses the impact of their disruption, and establishes RTOs and RPOs to guide continuity planning.
Which governance document formally authorizes a specific system to operate within an organization, acknowledging its risks?
Answer: Authority to Operate (ATO)
An Authority to Operate (ATO) is a formal decision by an authorizing official that accepts the residual risk of operating a system.
A CISO discovers that a cloud provider is subcontracting data processing to a fourth-party vendor without notification. This PRIMARILY violates which principle?
Answer: Due diligence in vendor chain management
Undisclosed subcontracting represents a failure of supply chain due diligence, which requires visibility and control over all parties handling organizational data.
Which of the following is an example of a leading indicator for measuring security program effectiveness?
Answer: Percentage of employees who completed security awareness training this quarter
Leading indicators measure proactive activities (like training completion) that predict future security posture, as opposed to lagging indicators that measure past failures.
When developing a compliance program, which approach ensures that controls satisfy multiple regulatory requirements simultaneously?
Answer: A unified control framework mapped to multiple regulatory requirements
A unified control framework with crosswalk mappings allows a single control to satisfy multiple regulatory requirements, reducing redundancy and cost.
What does the term 'residual risk' represent after security controls are implemented?
Answer: The risk that remains after all applicable controls have been applied
Residual risk is the remaining level of risk exposure after inherent risk has been reduced by implementing security controls.