Domain 1 Architect for Governance, Compliance, and Risk Management Flashcards
(10 cards)
Acceptable risk
A suitable level of risk commensurate with the potential benefits
of the organization’s operations as determined by senior
management.
Adequate Controls
Safeguards and countermeasures commensurate with the level
of risk.
Compliance
Adherence to a mandate; both the actions demonstrating
adherence and the tools, processes, and documentation that are
used in adherence.
Confidentiality
Preserving authorized restrictions on information access and
disclosure, including means for protecting personal privacy and
proprietary information.
Classification
Preserving authorized restrictions on information access and
disclosure, including means for protecting personal privacy and
proprietary information.
Data Owner/Controller
An entity that collects or creates PIl.
Difference between due care and due diligence
Due care is the legal concept,
Due diligence are the actions taken to demonstrate or provide due care
Shadow IT
IT services acquired and managed outside of the traditional IT
department.
The process of identifying and addressing any weaknesses or
gaps that could lead to a security breach.
Vulnerability management