Governance, Risk, and Compliance Flashcards
6 cards from real ISSAP practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 6 Governance, Risk, and Compliance flashcards as text
A security architect is designing a system for a financial institution that must comply with the Sarbanes-Oxley Act (SOX). A primary objective is to align IT processes with business goals and ensure robust internal controls over financial reporting. Which of the following governance frameworks is MOST suitable for achieving this objective?
Answer: COBIT (Control Objectives for Information and Related Technologies)
COBIT is a comprehensive framework for the governance and management of enterprise IT. It is specifically designed to bridge the gap between technical issues, business risks, and control requirements, making it highly suitable for achieving compliance with regulations like SOX that require strong internal controls and alignment between IT and business objectives. While other frameworks are useful, COBIT's core focus is on governance and its link to business goals.
As part of the NIST Risk Management Framework (RMF), a security architect is responsible for defining the initial set of security controls for a new information system. This selection is based on the system's security categorization. Which step of the RMF is being performed?
Answer: Select Controls
The 'Select Controls' step of the NIST RMF involves choosing an initial baseline of security controls for an information system based on its security categorization (determined in the 'Categorize System' step). The architect then tailors this baseline to align with the organization's specific risk tolerance and operational environment.
A global e-commerce company is developing a comprehensive risk management strategy. They want to adopt a set of high-level principles to guide the integration of risk management into all organizational activities, ensuring it is dynamic, customized, and structured. Which international standard provides such principles for risk management?
Answer: ISO 31000
ISO 31000 is an international standard that provides principles, a framework, and a process for managing risk. It is not specific to any industry and focuses on integrating risk management throughout an organization's governance, strategy, and operations. Its core principles include integration, a structured approach, customization, and continual improvement.
A security architect is embedding compliance requirements into the technology infrastructure from the initial design phase. This proactive approach ensures that controls for data protection, access management, and privacy are built-in rather than added later, significantly reducing the cost and effort of retrofitting. This practice is best described as which of the following?
Answer: Security by Design
Security by Design, also referred to as Secure by Design, is the principle of integrating security considerations and controls into the system development lifecycle from the very beginning. This approach ensures that compliance and security are fundamental components of the architecture, rather than afterthoughts that require costly retrofitting.
Which of the following is a primary role of a security architect in the context of Governance, Risk, and Compliance (GRC)?
Answer: Designing and developing security solutions that align with business strategy, policies, and regulatory requirements.
A security architect's primary role within GRC is to design security solutions and architectures that are aligned with the organization's vision, mission, strategy, policies, and external factors like laws and regulations. They translate GRC objectives into technical and architectural requirements, ensuring that the security posture supports business goals while managing risk and maintaining compliance.
A security architect at a multinational corporation is tasked with designing a security architecture that can adapt to a complex and constantly changing regulatory landscape. The architecture must provide a consistent set of reusable security services, such as identity management and network segmentation, across all business units. What is the main benefit of this architectural approach?
Answer: It provides standardization that simplifies demonstrating compliance across multiple regulations.
A well-designed security architecture that uses consistent, standardized building blocks and common security services simplifies the process of meeting diverse regulatory obligations. This consistency makes it easier to audit, manage, and demonstrate compliance across the enterprise, even when regulations change or overlap.