Line of Defense Flashcards

1
Q

1st Line: Operational Management

A

Business Units, IT, and Ops Teams “- Implement and manage controls.
- Identify and manage risks in daily operations.” “- Secure cloud configurations (e.g., storage, VMs).
- Manage user access.
- Monitor cloud resources.”

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

2nd Line: Risk Management & Compliance

A

Risk Managers, Compliance Officers, Security Teams “- Oversee operational teams.
- Develop policies, standards, and guidelines.
- Monitor compliance.” “- Use frameworks like ISO/IEC 27001.
- Assess cloud provider risks.
- Ensure GDPR or HIPAA compliance.”

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

3rd Line: Internal and External Audit

A

Internal Audit Teams, External Auditors “- Provide independent assurance.
- Evaluate controls and risk management.
- Report to leadership.” “- Conduct cloud audits (e.g., SOC 2, FedRAMP).
- Test data protection controls.
- Report findings.”

How well did you know this?
1
Not at all
2
3
4
5
Perfectly