Which of the following statements correctly describe the risk management lifecycle process?
For a particular risk assessment methodology (RAM), the control effectiveness score is calculated based on an individual assessment of controls. What are options for control identification? (Choose three.)
The Calculated Risk Score utilizes data from the Inherent and Residual Risk scores to determine an adjusted ALE and Score. What other data drives the adjustments?
Entity scoping is used for what?
Which of the following are Policy Lifecycle states included in the ServiceNow baseline? (Choose two.)
Jim is an Audit Manager. In addition to Audit Manager, which roles should be assigned to ensure he can
manage the audit process as well as other GRC functions related to audit? (Choose two.)
If you create a control manually and later decide to create them automatically, what will be the result?
What is the minimum role required for creating a policy acknowledgement campaign?
What are some characteristics of the ServiceNow Store? (Choose four.)
What happens when you assign an Entity Type to a Control Objective?
For classic risk assessment, indicator failure factor represents the impact of risk indicator failures on what score?
In which state is the Policy once all approvals are received?
The overall goal of Entity Classes is to:
Where does one go to configure the Regulatory Change Management impact assessment template?
What are the terms for level of risk before and after any actions are taken? (Choose two.)
Critical parts of a successful GRC implementation are understanding the customers current: (Choose three.)
Which of the following tables exist within the GRC: Profiles application scope? (Choose three.)