Principles and Models Flashcards
7 cards from real GRC practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Principles and Models flashcards as text
Which framework introduced the concept of 'Capability Maturity Model' adapted for GRC programs to measure process improvement?
Answer: CMMI
The Capability Maturity Model Integration (CMMI) provides a scale from Level 1 (Initial) to Level 5 (Optimizing) to measure the maturity of organizational processes including GRC.
In the context of GRC, 'control self-assessment' (CSA) is best described as:
Answer: A process where management and staff evaluate their own controls' effectiveness
Control self-assessment involves process owners and employees evaluating the adequacy and effectiveness of controls in their own area of responsibility.
Under the COBIT framework, which domain is primarily concerned with setting direction and aligning IT with business goals?
Answer: Align, Plan and Organize
The 'Align, Plan and Organize' (APO) domain in COBIT addresses how IT strategy and planning align with business objectives.
The FAIR (Factor Analysis of Information Risk) model is distinctive because it:
Answer: Quantifies information risk in financial terms
FAIR is a quantitative risk analysis model that expresses information risk in monetary terms, enabling direct comparison with business costs and benefits.
Which principle in governance theory holds that those who make decisions should be held answerable for the outcomes of those decisions?
Answer: Accountability
Accountability is the obligation of decision-makers to answer to stakeholders for their actions and the results those actions produce.
A 'key risk indicator' (KRI) differs from a 'key performance indicator' (KPI) in that a KRI:
Answer: Signals potential future risk events before they occur
KRIs are forward-looking metrics that provide early warning of increasing risk exposure, while KPIs typically measure historical performance.
In GRC frameworks, 'continuous monitoring' is preferred over periodic assessments primarily because it:
Answer: Provides near-real-time visibility into control effectiveness and risk posture
Continuous monitoring detects control failures and risk changes as they occur, rather than only at the point-in-time snapshot an annual assessment provides.