Quizlet GRC Flashcards
Profile/Entity
Records that aggregate GRC information related to a specific item
Authority Document
The regulations, certifications, frameworks, standards, and best practices for compliance with regulations
Citations
Records with the specific requirements cited by an Authority Document
Policy
internal practice ensure compliance and reduce Risk exposure
Control Objective
specific details that a process follows within a Policy
Unified Compliance Framework (UCF)
Compliance database serving for managing IT compliance requirements from around the world
Risk Criteria
Quantitative or Qualitative values against which level of Risk is evaluated
Residual Score
The score of the Risk after any response strategy is implemented
Risk Roles
Risk Admin, Risk Manager, Risk User, Risk Reader, Survey Reader
An entity can belong to more than one Entity Class?
false
A Profile can be related to one or more multiple profile types?
true
Issue
A GRC task that allows end users to document Control and Risk Issues and track the response to remediate or accept the issue
Indicator
A metric used to collect data to monitor Controls and Risks, and collect audit evidence
Risk Framework
A formalized process for managing Risk on an explicit basis
Control
The actual control activities that are to be performed by an organization
Risk Statement
A defined consequence that can occur if a threat exploits a vulnerability
Risk Register
A repository of the key attributes of potential and known Risk issues
Risk
Any threat or vulnerability that could adversely affect an organization’s business objectives.
Calculated Score
Derived from the inherent score and the residual score as an overall outcome
Inherent Likelihood
the likelihood of the identified Risk occurring before any response strategy is implemented
Inherent Risk
The level of risk before any actions and Controls are in place
Inherent Score
The score of the risk before any response strategy is implemented
Qualitative Impact
Calculated by Impact x likelihood
Quantitative Impact
Calculated by Single Loss Expectancy (SLE) x Annualized Rate of Occurrence (ARO) = Annualized Loss Expectancy (ALE)
Residual Likelihood
The likelihood of the identified Risk occurring after any response strategy is implemented
Residual Risk
The level of Risk after actions and Controls are in place
Compliance Roles
Compliance Developer, Compliance Admin, Compliance Manager, Compliance User, Compliance Reader, Survey Reader
GRC Roles
Legacy roles - do not use (GRC Developer, GRC Admin, GRC Manager, GRC User, GRC Reader)
What tables extend the Document table (sn_grc_document)?
Risk Framework, Policy, Authority Document
What tables extend the Content table (sn_grc_content)?
Risk Statement, Policy Statement, Citation
What tables extend the Item table (sn_grc_item)?
Risk, Control
Any component (Business Rules, Client Scripts, ACL, etc.) that is defined for the parent table applies to any tables extended from it
true
Can a Profile belong to one or more multiple Profile Types?
true
What roles can create Profile Classes, Profile Types, and Profiles?
Compliance Manager, Risk Manager
What role can create Issues, Indicators, Remediation Tasks, and Policy Exceptions?
Compliance Manager, Risk Manager
What roles can view Authority Documents and Citations?
Compliance Managers, Compliance Users
What roles can create Policies, Policy Statements, Policy Exceptions, Controls, Authority Documents, and Citations?
Compliance Managers, Compliance Users
What roles can view Risk Frameworks, Risk Statements, Assessments, and Risk Response tasks?
Risk Managers, Risk Users
What roles can create Risks, Risk Frameworks, and Risk Statements?
Risk Managers
What roles can create Risks?
Risk Managers, Risk Users