Quizlet GRC Flashcards
Profile/Entity
Records that aggregate GRC information related to a specific item
Authority Document
The regulations, certifications, frameworks, standards, and best practices for compliance with regulations
Citations
Records with the specific requirements cited by an Authority Document
Policy
internal practice ensure compliance and reduce Risk exposure
Control Objective
specific details that a process follows within a Policy
Unified Compliance Framework (UCF)
Compliance database serving for managing IT compliance requirements from around the world
Risk Criteria
Quantitative or Qualitative values against which level of Risk is evaluated
Residual Score
The score of the Risk after any response strategy is implemented
Risk Roles
Risk Admin, Risk Manager, Risk User, Risk Reader, Survey Reader
An entity can belong to more than one Entity Class?
false
A Profile can be related to one or more multiple profile types?
true
Issue
A GRC task that allows end users to document Control and Risk Issues and track the response to remediate or accept the issue
Indicator
A metric used to collect data to monitor Controls and Risks, and collect audit evidence
Risk Framework
A formalized process for managing Risk on an explicit basis
Control
The actual control activities that are to be performed by an organization
Risk Statement
A defined consequence that can occur if a threat exploits a vulnerability
Risk Register
A repository of the key attributes of potential and known Risk issues
Risk
Any threat or vulnerability that could adversely affect an organization’s business objectives.
Calculated Score
Derived from the inherent score and the residual score as an overall outcome
Inherent Likelihood
the likelihood of the identified Risk occurring before any response strategy is implemented
Inherent Risk
The level of risk before any actions and Controls are in place
Inherent Score
The score of the risk before any response strategy is implemented
Qualitative Impact
Calculated by Impact x likelihood
Quantitative Impact
Calculated by Single Loss Expectancy (SLE) x Annualized Rate of Occurrence (ARO) = Annualized Loss Expectancy (ALE)