Domain 1 Architect for Governance, Compliance, and Risk Management Flashcards

(10 cards)

1
Q

Acceptable risk

A

A suitable level of risk commensurate with the potential benefits
of the organization’s operations as determined by senior
management.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Adequate Controls

A

Safeguards and countermeasures commensurate with the level
of risk.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Compliance

A

Adherence to a mandate; both the actions demonstrating
adherence and the tools, processes, and documentation that are
used in adherence.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Confidentiality

A

Preserving authorized restrictions on information access and
disclosure, including means for protecting personal privacy and
proprietary information.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Classification

A

Preserving authorized restrictions on information access and
disclosure, including means for protecting personal privacy and
proprietary information.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Data Owner/Controller

A

An entity that collects or creates PIl.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Difference between due care and due diligence

A

Due care is the legal concept,
Due diligence are the actions taken to demonstrate or provide due care

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Shadow IT

A

IT services acquired and managed outside of the traditional IT
department.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

The process of identifying and addressing any weaknesses or
gaps that could lead to a security breach.

A

Vulnerability management

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q
A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly