← All GRC Flashcard Decks

Principles and Models Flashcards

7 cards from real GRC practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Principles and Models flashcards as text
  1. Which component of the COSO Internal Control framework addresses the organization's values, ethical standards, and the importance management places on integrity?

    Answer: Control Environment

    The Control Environment is the foundation of COSO's internal control framework, encompassing tone at the top, values, ethics, and organizational structure.

  2. In GRC terminology, what is 'risk tolerance' as distinct from 'risk appetite'?

    Answer: The acceptable variation around a risk appetite objective

    Risk tolerance defines the acceptable boundaries of variation around a specific objective, providing more granular guidance than the broader risk appetite statement.

  3. The principle of 'separation of duties' in GRC primarily serves to:

    Answer: Prevent any single individual from controlling all aspects of a critical process

    Separation of duties is a key internal control that distributes tasks across multiple people to reduce the risk of error or fraud.

  4. Under the NIST Risk Management Framework (RMF), what is the correct order of the first three steps?

    Answer: Prepare, Categorize, Select

    The NIST RMF steps in order are: Prepare, Categorize, Select, Implement, Assess, Authorize, and Monitor.

  5. Which governance principle requires that board members and executives avoid situations where personal interests conflict with organizational interests?

    Answer: Conflict of interest management

    Conflict of interest management requires individuals to disclose and abstain from decisions where personal gain could compromise their objectivity.

  6. A 'heat map' in risk management is used to:

    Answer: Visually represent risks by plotting likelihood against impact

    A risk heat map plots risks on a matrix with likelihood on one axis and impact on the other, providing a visual prioritization tool.

  7. Which GRC model concept refers to the organization's total exposure to risk before any controls or mitigation are applied?

    Answer: Inherent risk

    Inherent risk is the natural level of risk in a process or activity before management applies controls to reduce it.