CIS – Risk and Compliance Brain Dump Flashcards
what is not a key Compliance Indicator
Reference
Types of key Compliance Indicator
Basic
Manual
PA Indicator
Scripted
Who should be on the core implementation team for a GRC implementation?
Risk and compliance experts
ServiceNow developer team
CMDB Expert
which response task helps in reducing overall risk
mitigate
Which of the following extends from items
controls
policy
What does a restricted script include that processes Risk responses?
RiskUtilsBaseV2
The Entity Filter record requires which mandatory field to be completed?
Conditions
what implementers have to do to configure confidentiality?
Configure and identify allowed user
UCF Control documents import into which table in ServiceNow?
Authority Documents
In classic risk assessment, SLE can be used to calculate the Risk Rating, what other factors impact the risk rating?
Control test failure and indicator failure
Once all Approvals are received, the Policy is in which state?
published
Which table extends from Content Table?
Risk Statement
What tables are extended using the document table in GRC
Policy
Authority document
Risk Framework
SLA definitions can be created on which tables
Issue
Risk response task
What feature would you use to build out a hierarchy and relationships between entities within the organization?
Profile Types and Profiles
Select the correct statement about Risk Scoring formulas
SLE X ARO = ALE
What new related list was added to the risk statement and entity records after migrating to advanced risk assessment?
Aggregated risk related list
Commonly used tables when profile scoping include
Location
Company
Department
Asset
what role is given to external auditor team to view all policies and controls
sn_audit.external_auditor
Which of the following tables exist within the GRC: Profiles application scope?
Document
Content
Indicator
What does risk register consist of?
The repository of all Identified Risk
which assessments can be configured in RAM
Inherent
Residual
Control
True/ False: An entity type can contain entities from different entity classes and tiers.
True
What is the relationship table that relates Risks to controls?
sn_risk_m2m_risk_control
What minimum role is needed to bulk initiate risk assessments using the risk assessment scheduler?
sn_risk.manager
What ensures that every time you create a Profile from a specific table, the Class of the Profile is set according to the rule?
Profile class rules
Table that stores relationships for Entities?
sn_grc_m2m_profile_profile_type
While Policy Records are in Review state, reviewers can do what?
Send the Policy forward by requesting approval
Send the Policy back to Draft
ServiceNow GRC helps eliminate an old inefficient work model by removing what?
Silos
“Santa Clara Facility” and “Boston Facility” are examples of what?
Profiles
All the following are PARENT tables which exist within the GRC Entities application scope EXCEPT.
Indicator
Which roles are inherited when a user is given the sn_audit.user role?
sn_grc.reader
sn_compliance.reader
sn_risk.reader
What is the condition that must exist to edit the factor guidance of a published risk assessment methodology (RAM)
All assessment instance records are deleted
reasons customers see for implementing GRC
efficiency
workflow driven
integrated reporting and transparency
Which of the following statements correctly describe the risk management lifecycle process?
Identify and Plan, Assess, Control, Review
The compliance score calculation may be modified by changing which control factor?
Control Weight
Which field in Policy works on redlining functionality in Office365?
Contributor
Concerning the two approaches to customer frameworks:
1) The Unified Compliance Framework (UCF)
2) Customer Controls, which statement is true?
Both approaches can be used, with no designation necessary
Which role/s can create the Policy Acknowledgements?
Compliance User
common tables used in entity filters
location
service