GRC Flashcards
How many privacy principles make up the OECD privacy principles
8
GDPR only applies to people living in Australia (true or false)
False
This was developed for accountants
GAPP
All of the following are privacy challenges in the modern world except :
Geolocation considerations
Complex contracts
Fragmentation of laws
Granting end users too much privacy
Granting end users too much privacy
Which of the following help drive security
OECD Pivacy principles
E.U. general privacy principles
NIST privacy framework
Generally accepted privacy principles
Generally accepted privacy principles
Profitability is impacted by risk oversight and asset management but not by the enterprise architecture (true or false)
False
In the EA model enterprise governance is found at layer 4 (true or false)
False
Which layer of the enterprise architecture reference model deals with the business units
Layer 2
The first step in the TOGAF model is migration planning (true or false)
False
Security is not built into the SABSA model so its important for organizations to also implement zero trust (true or false)
False
What does BIA stand for?
Business impact Analysis
What is the purpose of bcm
Focuses on the organization’s strategy for business resilience
What are the steps of NIST SP 800-34
Determine mission processes and recovery criticality
Identify resource requirements
Identify recovery priorities
What is RPO?
recovery point objective, represents the point and time prior to a disruption or system outage. To which business process data must be recovered after an outage
What is an rto?
It defines the maximum amount of time that a system resource can remain unavailable before there is an unexceptionable impact on other systems resources, mission/business processes and mtd
What’s an mtd?
Represents the total amount of time leaders/managers are willing to accept for a mission/business process outage or disruption and includes all impact considerations
How many influential business drivers are there?
6
What does CMMI STAND FOR
capability maturity model integration
What are the significant compliance drivers used to manage a grc program effectively
Organizational, contractual, regulatory
True or false
A code of ethics covers extreme care
True
NIST SP 800-34 specifies the nine steps that are typically involved in accomplishing the business impact analysis (BIA)
TRUE OR fALSE
False
How many privacy principles make up the OECD privacy principles
8
True or false
In the EA model, enterprise governance is found at layer 4
False
PCI-DSS has how many objectives
6
True or false
Profitability is impacted by risk oversight and asset management, but not by the enterprise architecture
False
True or false
GDRP only applies to people living in Australia
False
BIA stands for?
Business impact analysis
The ceo always reports directly to the grc lead because grc is deemed a critical component of the business
True or false
False
True or false
Security is not built into the SABSA model so its important for organizations to also implement zero trust
False
True or false
Business continuity management is solely focused on the technical recovery of systems and processes after an event occurs
False