GRC: Policy and Compliance Flashcards

1
Q

Compliance Developer contains what roles

A

sn_grc.developer, sn_compliance.admin

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

sn_compliance.developer performs what functions

A

Responsible for maintaining various aspects of the platform, such as creating workflows, reports, dashboards, additional modules, and other platform specific content

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

sn_compliance.reader role performs what functions?

A

Read only access to all modules of the policy and compliance App

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Complaince Reader contains what roles?

A

Sn_grc.reader

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What are the policy record states?

A

Draft, Review, Awaiting Approval, Published, Retired

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What are the control objective states?

A

Active, inactive

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What are the control record states?

A

Draft, attest, review, monitor, retire

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What are the policy exception states?

A

New, pending verification (if verification rules are turned on), analyze, review, awaiting approval, approved, closed

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What are the policy acknowledgment states?

A

New, pending acknowledgment, closed, cancelled

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What tables exist within the GRC: Profiles scope?

A

Document, Policy, Indicator

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What are the two ways you can prevent certain users from seeing certain modules?

A
  1. ACL customization, 2. Before Query Business Rule to restrict row access (Return only certain records if you are member of X group or have X role etc)
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What is the purpose of Entity Scoping?

A

Automatically create and remove entities as needed per system and business service creation in other groups. These define groups that you can apply to Control Objectives, Risks Statements, and Engagements to define what needs to be evaluated

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What is the business rule that auto updates entities, controls and risks?

A

GRC Profile Generation; it is a scheduled job set by default to run every hour

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Can entities be associated to multiple entity types?

A

Yes, entities can be associated with multiple entity types. Many to Many Relationship

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Can an entity be related to multiple Entity Classes?

A

No, an entity can have only one Entity Class assigned

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What are possible starting points for Entity Scoping?

A

Identify the current items that are being tracked; look at what needs to be compliant and what roles/teams/business units that are responsible; review risk register and control library; existing auditable units

17
Q

How granular should you approach entity scoping?

A

Depends on the use case; Operational level vs a Strategic level approach. You will have a mixture but you should try to reduce the replication of effort. ie evaluate on a VM level or since all VM’s are created from the same image; evaulate just the image instead

18
Q

What are common tables to be used within entity filters?

A

core_company, cmn_department, cmn_location, cmdb_ci_service, cmdb_ci_db_instance, sys_user_group, cmdb_ci_group, sysapproval_group, cmdb_ci_business_process

19
Q

Are entities limited to CMDB or Core platform tables?

A

No, you can leverage any table in or outside of the cmdb for creating your entity filters for entity types

20
Q

When a record no longer matches an entity filter, what occurs?

A

The related entity, controls, risks and indicators are removed from the entity type and the downstream controls retired

21
Q

Entity owner field by default is defined and controlled by what?

A

Entity owner field is defined by the first entity filter that runs; any changes on the original cmdb record does not update the entity after creation

22
Q

Does ownership of controls cascade down from changes of owners on the entity record?

A

No; by default the system doesn’t cascade down changes from cmdb, to entity, to controls/risks

23
Q

What does entity roll-up define the roll-up of?

A

Entities, Controls, and Risks. Risk Assessment Methodologies are defined for an entity class. Entity Classes determine which entities can be assigned an impact assessment

24
Q

What do Entity Classes allow for that Entity Types do not?

A

It allows for the mixing and matching of Entities with different parent tables

25
Q

What is the main purpose of the GRC Workbench interface?

A

It allows for the easy management of entity classes

26
Q

Entity class will define the upstream and downstream entities, risk and controls

A
27
Q

What are the GRC: Profiles scoped tables?

A

sn_grc_document, sn_grc_content, sn_grc_item

28
Q

What is the purpose of the “days after valid to date” System Property?

A

This is the number of days after the valid to date in which a Policy record is moved back to draft or review state. It is only moved to draft if there are no assigned reviewers on the record which should not be the case as it is mandatory.

29
Q

Who can send a policy back to draft after it has been moved to the Review state?

A

Anyone assigned as a Reviewer, Owner or someone within the assigned Owning Group

30
Q

When is the knowledge article related to a policy published?

A

It is published when the policy record is moved to the published state. The system will track versioning as a policy is republished after a review cycle

31
Q

What is the purpose of a policy acknowledgement campaign?

A

It is to make sure that people within the company have visibility to changes in policy and proof of receipt

32
Q

How do you define the scope of a policy acknowledgement campaign?

A

You would set this via the audience within the Policy Acknowledgement > Audience module.

33
Q

When would you be able to setup and send out a policy acknowledgement campaign?

A

You are only able to set an audience when the policy has been set to the published state