Control Objectives Flashcards

1
Q

Control objectives can only be scoped with an entity type when ______

A

in Active state

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Control objectives can be associated with more than one __________ and the follow that __________ record lifecycle

A

policy

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Control objectives can be related to these 3 kinds of template records:

A

test templates, indicator templates, and performance analytics indicators

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What are the 3 types of Controls?

A

Standard (one control per entity), unique (multiple controls per entity), and common (one primary control-entity pair)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What is the Control record lifestyle?

A

Draft -> Attest -> Review -> Monitor -> Retired

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What role is required to modify/edit controls and move into Attest state?

A

sn_compliance.user

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Who can complete control attestations?

A

only assigned attestation respondents

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What should be done if an attestation respondent is not available?

A

The control returned to draft and reassigned

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What role is required to review a control and move into Monitor or return to Draft?

A

sn_compliance.manager

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

what may be scheduled for a control in the Monitor state?

A

Indicators

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What happens to controls when the scoped entity becomes inactive?

A

They automatically retire

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

How do unique controls provide greater control objective granularity?

A

Create new controls with unique names scoped within an existing entity, can assign different control owners, and uniquely named controls are included in the compliance score

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Which type of control is only available on the Compliance Workspace?

A

common controls

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What happens to a standard control when it is converted to a common control?

A

retired

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

How many entities can be processed at a time when migrating entities from standard controls to be reliant entities?

A

15

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What is the difference between standard and common control function?

A

standard controls are individual for each entity relationship, require testing for each entity, whereas common controls have one primary entity relationship where testing occurs and reliant entities inherit the test results

17
Q

What are the steps to set up a common control where no controls currently exist?

A

Create a standard control for the primary entity, convert to a common control, add entity type to the common control

18
Q

What are the steps to set up a common control when standard controls already exist?

A

convert standard control of primary entity to a common control, convert remaining standard controls to reliant entities, remove entity type from control objective, add entity type to common control

19
Q
A