โ† All GRC Flashcard Decks

Principles and Models Flashcards

7 cards from real GRC practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Principles and Models flashcards as text
  1. Which framework introduced the concept of 'Capability Maturity Model' adapted for GRC programs to measure process improvement?

    Answer: CMMI

    The Capability Maturity Model Integration (CMMI) provides a scale from Level 1 (Initial) to Level 5 (Optimizing) to measure the maturity of organizational processes including GRC.

  2. In the context of GRC, 'control self-assessment' (CSA) is best described as:

    Answer: A process where management and staff evaluate their own controls' effectiveness

    Control self-assessment involves process owners and employees evaluating the adequacy and effectiveness of controls in their own area of responsibility.

  3. Under the COBIT framework, which domain is primarily concerned with setting direction and aligning IT with business goals?

    Answer: Align, Plan and Organize

    The 'Align, Plan and Organize' (APO) domain in COBIT addresses how IT strategy and planning align with business objectives.

  4. The FAIR (Factor Analysis of Information Risk) model is distinctive because it:

    Answer: Quantifies information risk in financial terms

    FAIR is a quantitative risk analysis model that expresses information risk in monetary terms, enabling direct comparison with business costs and benefits.

  5. Which principle in governance theory holds that those who make decisions should be held answerable for the outcomes of those decisions?

    Answer: Accountability

    Accountability is the obligation of decision-makers to answer to stakeholders for their actions and the results those actions produce.

  6. A 'key risk indicator' (KRI) differs from a 'key performance indicator' (KPI) in that a KRI:

    Answer: Signals potential future risk events before they occur

    KRIs are forward-looking metrics that provide early warning of increasing risk exposure, while KPIs typically measure historical performance.

  7. In GRC frameworks, 'continuous monitoring' is preferred over periodic assessments primarily because it:

    Answer: Provides near-real-time visibility into control effectiveness and risk posture

    Continuous monitoring detects control failures and risk changes as they occur, rather than only at the point-in-time snapshot an annual assessment provides.