GRC: Policy and Compliance Flashcards
Compliance Developer contains what roles
sn_grc.developer, sn_compliance.admin
sn_compliance.developer performs what functions
Responsible for maintaining various aspects of the platform, such as creating workflows, reports, dashboards, additional modules, and other platform specific content
sn_compliance.reader role performs what functions?
Read only access to all modules of the policy and compliance App
Complaince Reader contains what roles?
Sn_grc.reader
What are the policy record states?
Draft, Review, Awaiting Approval, Published, Retired
What are the control objective states?
Active, inactive
What are the control record states?
Draft, attest, review, monitor, retire
What are the policy exception states?
New, pending verification (if verification rules are turned on), analyze, review, awaiting approval, approved, closed
What are the policy acknowledgment states?
New, pending acknowledgment, closed, cancelled
What tables exist within the GRC: Profiles scope?
Document, Policy, Indicator
What are the two ways you can prevent certain users from seeing certain modules?
- ACL customization, 2. Before Query Business Rule to restrict row access (Return only certain records if you are member of X group or have X role etc)
What is the purpose of Entity Scoping?
Automatically create and remove entities as needed per system and business service creation in other groups. These define groups that you can apply to Control Objectives, Risks Statements, and Engagements to define what needs to be evaluated
What is the business rule that auto updates entities, controls and risks?
GRC Profile Generation; it is a scheduled job set by default to run every hour
Can entities be associated to multiple entity types?
Yes, entities can be associated with multiple entity types. Many to Many Relationship
Can an entity be related to multiple Entity Classes?
No, an entity can have only one Entity Class assigned