CIS – Risk and Compliance Brain Dump Flashcards
what is not a key Compliance Indicator
Reference
Types of key Compliance Indicator
Basic
Manual
PA Indicator
Scripted
Who should be on the core implementation team for a GRC implementation?
Risk and compliance experts
ServiceNow developer team
CMDB Expert
which response task helps in reducing overall risk
mitigate
Which of the following extends from items
controls
policy
What does a restricted script include that processes Risk responses?
RiskUtilsBaseV2
The Entity Filter record requires which mandatory field to be completed?
Conditions
what implementers have to do to configure confidentiality?
Configure and identify allowed user
UCF Control documents import into which table in ServiceNow?
Authority Documents
In classic risk assessment, SLE can be used to calculate the Risk Rating, what other factors impact the risk rating?
Control test failure and indicator failure
Once all Approvals are received, the Policy is in which state?
published
Which table extends from Content Table?
Risk Statement
What tables are extended using the document table in GRC
Policy
Authority document
Risk Framework
SLA definitions can be created on which tables
Issue
Risk response task
What feature would you use to build out a hierarchy and relationships between entities within the organization?
Profile Types and Profiles
Select the correct statement about Risk Scoring formulas
SLE X ARO = ALE
What new related list was added to the risk statement and entity records after migrating to advanced risk assessment?
Aggregated risk related list
Commonly used tables when profile scoping include
Location
Company
Department
Asset
what role is given to external auditor team to view all policies and controls
sn_audit.external_auditor
Which of the following tables exist within the GRC: Profiles application scope?
Document
Content
Indicator
What does risk register consist of?
The repository of all Identified Risk
which assessments can be configured in RAM
Inherent
Residual
Control
True/ False: An entity type can contain entities from different entity classes and tiers.
True
What is the relationship table that relates Risks to controls?
sn_risk_m2m_risk_control