GRC Udemy Flashcards

1
Q

Set of policies, rules, or practices that a company uses to achieve its business goals

A

Governance

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Potential for loss or harm to the IT infrastructure

A

Risk

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Adherence of organizations to laws regulations, standards, policies and guidelines

A

Compliance

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Structured way to align IT with business goals while managing risks and meeting all industry regulations

A

GRC

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

GRC Disciplines. Name 3

A

-governance and oversight
-strategy and performance
-risk management
-compliance and ethics
-information security
-audit and assurance

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

3 lines defense model

A
  1. Business,
  2. security and
  3. internal audit

Governing body
Management
Internal audit

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Meet stakeholders needs by providing value.

Achieved through policy rules and practices

A

Governance

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Soc

Compliance framework

A

Service organizations control

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

NIST Framework
5 cores

A

Identify
Protect
Detect
Respond
Recover

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Determines what exists, dangers involved and connect to company goal is what most core function?

Ex. Asset and risk management, governance

A

Identify

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Safeguarding assets and data. Access control and data encryption. Nist

A

Protect

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q
A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Safeguarding asset and data. Incident detection monitoring

A

Detect

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Mitigating impact of risk. Notify stakeholders and keep operations up

A

Respond

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Repair and restore, effective response

A

Recover

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Requirement for ISMS. 93 controls.