CRISC Exam | Comprehensive Questions and
Answers | A+ Graded | With Expert Solutions
Save
Practice questions for this set
Learn 1 /7 Study with Learn
Entity responsible for controls that span the enterprise
Choose an answer
What is the difference between a
1 2 What is a threat agent?
standard and a policy?
Which framework is developed by
ISACA and integrates other
frameworks?
3 a) (Val) IT 4 Common Controls Provider
b) IT Assurance Framework (ITAF)
c) COBIT 5
d) Risk IT
Don't know?
, Terms in this set (102)
What is the difference between a Standard = A mandatory action, explicit rules,
standard and a policy? controls or configuration settings that are
designed to support and conform to a policy. A
standard should make a policy more meaningful
and effective by including accepted
specifications for hardware, software or behavior.
Standards should always point to the policy to
which they relate.
Policy = IT policies help organizations to properly
articulate the organization's desired behavior,
mitigate risk and contribute to achieving the
organization's goals.
What are the 4 risk elements? Threats, Vulnerabilities, Likelihood, and Impact.
Threats exploit vulnerabilities and the level of risk
is based on likelihood and the impact to the
system.
Describe risk appetite vs. risk Risk appetite is how much risk an organization is
tollerance willing to endure; Risk Tolerance is how much
variation from that amount is acceptable.
Name the 6 steps of the NIST Risk 1. Categorize Information Systems
Management Framework (RMF) 2. Select Security Controls
3. Implement Security Controls
4. Assess Security Controls
5. Authorize Information Systems
6. Monitor Security Controls
Answers | A+ Graded | With Expert Solutions
Save
Practice questions for this set
Learn 1 /7 Study with Learn
Entity responsible for controls that span the enterprise
Choose an answer
What is the difference between a
1 2 What is a threat agent?
standard and a policy?
Which framework is developed by
ISACA and integrates other
frameworks?
3 a) (Val) IT 4 Common Controls Provider
b) IT Assurance Framework (ITAF)
c) COBIT 5
d) Risk IT
Don't know?
, Terms in this set (102)
What is the difference between a Standard = A mandatory action, explicit rules,
standard and a policy? controls or configuration settings that are
designed to support and conform to a policy. A
standard should make a policy more meaningful
and effective by including accepted
specifications for hardware, software or behavior.
Standards should always point to the policy to
which they relate.
Policy = IT policies help organizations to properly
articulate the organization's desired behavior,
mitigate risk and contribute to achieving the
organization's goals.
What are the 4 risk elements? Threats, Vulnerabilities, Likelihood, and Impact.
Threats exploit vulnerabilities and the level of risk
is based on likelihood and the impact to the
system.
Describe risk appetite vs. risk Risk appetite is how much risk an organization is
tollerance willing to endure; Risk Tolerance is how much
variation from that amount is acceptable.
Name the 6 steps of the NIST Risk 1. Categorize Information Systems
Management Framework (RMF) 2. Select Security Controls
3. Implement Security Controls
4. Assess Security Controls
5. Authorize Information Systems
6. Monitor Security Controls