Implementation Planning 5% Flashcards
- Who should be on the core implementation team for a GRC implementation:
a. Platform experts
b. Board member
c. Internal audit
d. External audit
e. Risk assessor
f. CISO
a. Platform Experts
c. Internal Audit
(The exam will include CEO, board member as choices - they are stakeholders, not part of implementation.)
Implementer side: • SN platform experts • Risk and compliance experts • SN developer • CMDB developer • UI design team • Organizational change management
Customer side: • Risk and Compliance experts • CMDB process owner • Foundation data process owners • Security operations • Internal audit
Best Practices states that Risk Management should be implemented before Compliance.
a. Yes
b. No
b. No
- Which of the following should be considered when estimating the size of an RCI Implementation Project? (select all that apply)
a. Number of silos that currently manage risk.
b. How many regulations they want to track
c. Maturity of current risk process
d. How much time their GRC business staff has for the project
e. How much time their ServiceNow staff has for the project
f. Experience with ServiceNow
All:
a. Number of silos that currently manage risk.
b. How many regulations they want to track
c. Maturity of current risk process
d. How much time their GRC business staff has for the project
e. How much time their ServiceNow staff has for the project
f. Experience with ServiceNow
- What is the minimum role that a user must have to approve a Policy?
a. Compliance User
b. Compliance Manager
c. Compliance Admin
a. Compliance User
- What roles can create/update Entity Types?
a. Compliance User
b. Compliance Manager
c. Compliance Admin
d. Risk User
e. Risk Manager
f. Risk Admin
b. Compliance Manager
c. Compliance Admin
e. Risk Manager
f. Risk Admin
- What role can answer a Risk Assessment?
a. Does not need a role
b. Risk User
c. Compliance user
d. Compliance Manager
e. Risk admin
f. Risk Assessment Creator
g. Compliance Admin
h. Risk Manager
a. Does not need a role
What role can create a Risk Assessment?
a. Does not need a role
b. Risk User
c. Compliance user
d. Compliance Manager
e. Risk admin
f. Risk Assessment Creator
g. Compliance Admin
h. Risk Manager
f. Risk Assessment Creator
- What role can answer a control attestation?
a. Does not need a role
b. Risk User
c. Compliance user
d. Compliance Manager
e. Risk admin
f. Risk Assessment Creator
g. Compliance Admin
h. Risk Manager
a. Does not need a role
What role can create policies?
a. Does not need a role
b. Risk User
c. Compliance user
d. Compliance Manager
e. Risk admin
f. Risk Assessment Creator
g. Compliance Admin
h. Risk Manager
c. Compliance user
What role can approve policies?
a. Does not need a role
b. Risk User
c. Compliance user
d. Compliance Manager
e. Risk admin
f. Risk Assessment Creator
g. Compliance Admin
h. Risk Manager
c. Compliance user
What role can submit a control for attestation?
a. Does not need a role
b. Risk User
c. Compliance user
d. Compliance Manager
e. Risk admin
f. Risk Assessment Creator
g. Compliance Admin
h. Risk Manager
c. Compliance user
What role can create an issue (risk)?
a. Does not need a role
b. Risk User
c. Compliance user
d. Compliance Manager
e. Risk admin
f. Risk Assessment Creator
g. Compliance Admin
h. Risk Manager
b. Risk User
What role can create an indicator template (risk)?
a. Does not need a role
b. Risk User
c. Compliance user
d. Compliance Manager
e. Risk admin
f. Risk Assessment Creator
g. Compliance Admin
h. Risk Manager
h. Risk Manager
What role can create a policy exception from a control issue?
a. Does not need a role
b. Risk User
c. Compliance user
d. Compliance Manager
e. Risk admin
f. Risk Assessment Creator
g. Compliance Admin
h. Risk Manager
c. Compliance user
What role can create retire policies?
a. Does not need a role
b. Risk User
c. Compliance user
d. Compliance Manager
e. Risk admin
f. Risk Assessment Creator
g. Compliance Admin
h. Risk Manager
d. Compliance Manager