โ† All GRC Flashcard Decks

IT Governance and Cybersecurity Flashcards

7 cards from real GRC practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 IT Governance and Cybersecurity flashcards as text
  1. Which COBIT 5 principle states that IT governance should address the needs of all stakeholders, not just the IT department?

    Answer: Meeting stakeholder needs

    The 'Meeting Stakeholder Needs' principle ensures governance creates value by balancing benefits, risk, and resource use across all stakeholders.

  2. An organization wants to measure the effectiveness of its cybersecurity controls. Which metric best reflects the mean time to detect a security incident?

    Answer: MTTD (Mean Time to Detect)

    MTTD measures the average time between when an incident occurs and when it is identified by the security team.

  3. Under NIST SP 800-53, which control family specifically addresses security planning at the organizational level?

    Answer: Planning (PL)

    The Planning (PL) control family in NIST SP 800-53 covers system security plans and rules of behavior.

  4. A company's board requires quarterly cybersecurity reports. Which governance artifact best satisfies this requirement?

    Answer: Security scorecard with KPIs and KRIs

    A security scorecard summarizing KPIs and KRIs translates technical metrics into business-relevant information for board-level audiences.

  5. Which IT governance framework is specifically designed for IT service management and aligns IT services with business needs?

    Answer: ITIL

    ITIL (Information Technology Infrastructure Library) provides best practices for IT service management to align IT services with business requirements.

  6. In cybersecurity governance, what does a 'tone at the top' primarily influence?

    Answer: Security culture and employee behavior

    Tone at the top refers to leadership attitudes that shape organizational security culture and how seriously employees treat security policies.

  7. Which document formally defines the cybersecurity responsibilities of third-party vendors and their obligations to protect organizational data?

    Answer: Third-Party Risk Management Agreement / Vendor Contract

    Third-party risk management agreements or vendor contracts legally bind vendors to specific cybersecurity obligations and data protection requirements.