Compliance-supporting processes Flashcards

1
Q

what are the benefits of compliance score calculation?

A

a nuanced result, key operational insights, and enables remediation

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What is the default weight for all controls?

A

10

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

How is compliance score calculated?

A

weight of compliant controls divided by weight of all controls times 100

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What actions trigger recalculation of compliance score?

A

reliant entities are added or removed, common control retired or converted to standard control, common control changes its compliance status or weighting

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What is the policy acknowledgement campaign lifecycle?

A

New, Pending acknowledgement, Closed, Canceled

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What are the enhancements to policy acknowledgement in March 2021 release?

A

frequency on policy record to autoschedule, acknowledgement tasks sent to new members added to audiences, due date can be extended for new members, and additional email notifications

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

When is the audience of a policy acknowledgement campaign identified?

A

after campaign set up

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Who can set up a campaign, set schedule, and extend valid to date?

A

Policy owner, compliance user and above

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Who can identify campaign audience and add users for ongoing campaign?

A

compliance manager and above

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What happens when a policy acknowledgement campaign is pending acknowledgement?

A

instances are created for all users in the audience list, policy is presented on Employee Center with due date, and employee responses are captured

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Policy acknowledgement audience can consist of….?

A

users, groups, newly defined user filter

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What are the baseline options for a policy acknowledgement campaign audience receiving requests?

A

accept, decline, request exception

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Who can cancel a policy acknowledgement campaign?

A

compliance manager or campaign owner

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What happens when a campaign is overdue?

A

closed

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What are the 5 configuration steps for a policy acknowledgement campaign?

A

Create audience, set up campaign, set properties, respond to requests, view responses and statuus

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What is the path to create an audience for a policy acknowledgement campaign?

A

Policy and Compliance > Policy Acknowledgement > Audience

17
Q

What is the path to set up a policy acknowledgement campaign?

A

Policy and Compliance > Policy and Procedures > Policies

18
Q

What is the path to set properties of a policy acknowledgement campaign and what role is required?

A

Policy and Compliance > Administration > Properties. compliance admin

19
Q

Where can Policy acknowledgement campaign audience members complete acknowledgement requests?

A

Now Platform or Service Portal

20
Q

What is the path to view campaign responses and statuses and what role is required?

A

Policy and Compliance > Policy Acknowledgement > Overview. compliance reader

21
Q

Policy table extends from the ________ table

A

Document

22
Q

Acknowledgement campaign extends from the ______ table

A

Task

23
Q

What is the compliance case workflow?

A

Report case, triage and investigate, resolve, post case review, close

24
Q

Where can a user go to create a policy exception request?

A

Employee center, compliance workspace, policy exceptions module, control objective record, issue record

25
Q

What roles are required to request a policy exception?

A

sn_grc.business_user or sn_grc.business_user_lite

26
Q

A policy exception cannot be approved if the control objective ….?

A

is without controls or only has controls in draft or retired state

27
Q

What are the Approval options for a policy exception?

A

Approve, reject, one-time extension

28
Q

What is the associated flow for verification of a policy exception?

A

Generate initial approvals for policy exception

29
Q

What is the associated flow for approval of a policy exception?

A

Generate final approvals for policy exception

30
Q

What sets the substate to awaiting approvals if there are verification rules for an exception?

A

the Set Policy Exception Substate business rule

31
Q

exceptions submitted via ___________ are based on a _________ and bypass the __________process

A

service portal or employee center, record producer, verification

32
Q

What will the final approvals flow do when there is no approval rule?

A

run a script that obtains the impacted control owners and sets them as approvers

33
Q

What is the policy exception record lifecycle?

A

New > Analyze > Review > Awaiting Approval > Approved > Closed