CIS – Risk and Compliance flashcards
SERVICENOW · CIS – Risk and Compliance (CIS-RC)
Flash cards I used when studying for SN GRC. Hope it helps.
Certification Summary
The ServiceNow Certified Implementation Specialist - Risk and Compliance exam targets consultants tasked with building and configuring the GRC suite, rather than those who simply navigate the interface. Most people take this because a partner status requires a specific number of certified bodies, so expect questions that assume you know how to map control objectives to entities without breaking the underlying table structure.
Expect the exam to focus on Entity Scoping, Policy and Compliance, and Risk Implementation, which account for 75 percent of the content. The remaining sections cover GRC Overview, Implementation Planning, Audit Management, and Extended Capabilities. You will need to demonstrate how to configure the relationship between control tests and audit engagements within the GRC module.
You have mastered every card in this deck.
Pass complete.
Log in to mark cards as mastered and track progress.
The Imposter Hunt
The Imposter Hunt (Unlocked!)
Prove your knowledge to unlock this challenge.
Test your knowledge and spot the fake definitions.
Log in and master this deck to unlock.
All cards (150)
Scroll to review fronts and backs
Card 1
Front
GRC
Back
Governance, Risk, Compliance
Card 2
Front
Risk appetite
Back
How much risk we'll take to hit goals
Card 3
Front
Risk tolerance
Back
Acceptable variance from risk appetite
Card 4
Front
Control vs Policy
Back
Control = action to manage risk
Card 5
Front
Compliance
Back
Meeting external regs, internal policies
Card 6
Front
Risk framework
Back
Structured approach to identify, assess, respond to risk
Card 7
Front
Issue
Back
Something's not right
Card 8
Front
Control objective
Back
What a control aims to achieve
Card 9
Front
Attestation
Back
Proof a control is working
Card 10
Front
Audit engagement
Back
Planned review of controls
Card 11
Front
Key Risk Indicator KRI
Back
Metric showing increasing risk exposure
Card 12
Front
Key Performance Indicator KPI
Back
Metric showing how well objectives are met
Card 13
Front
Authority document
Back
Law, regulation, standard
Card 14
Front
Continuous monitoring
Back
Automated checks for control performance
Card 15
Front
Control owner
Back
Person responsible for a control's effectiveness
Card 16
Front
Implementation Planning
Back
Get the requirements right
Card 17
Front
Requirements gathering
Back
Talk to the business
Card 18
Front
Phased approach
Back
Start small
Card 19
Front
MVP
Back
Minimum Viable Product
Card 20
Front
Stakeholder identification
Back
Who cares?
Card 21
Front
Data migration strategy
Back
Old data into new system
Card 22
Front
Integration points
Back
Where does this talk to other systems?
Card 23
Front
Testing plan
Back
Prove it works
Card 24
Front
Entity Scoping
Back
What needs GRC?
Card 25
Front
Entity Type
Back
Template for similar entities
Card 26
Front
Entity Class
Back
High-level grouping
Card 27
Front
Hierarchy of Entities
Back
Parent-child relationships
Card 28
Front
Manual Entity Creation
Back
For unique things
Card 29
Front
Automated Entity Creation
Back
From CMDB
Card 30
Front
CMDB Integration for Entities
Back
CI data becomes entity data
Card 31
Front
Attributes for Entities
Back
Data fields
Card 32
Front
Entity Filter
Back
Target specific entities for assessments, policies
Card 33
Front
Risk Statement Scoping
Back
Which risks apply to which entities
Card 34
Front
Control Scoping
Back
Which controls apply to which entities
Card 35
Front
Policy Scoping
Back
Which policies apply to which entities
Card 36
Front
Profile Type
Back
Another name for Entity Type
Card 37
Front
Profile Class
Back
Another name for Entity Class
Card 38
Front
Dependent Entities
Back
If this fails, what else breaks?
Card 39
Front
Relationship Editor
Back
Map dependencies between entities
Card 40
Front
Entity Owner
Back
Who's accountable for this entity
Card 41
Front
Entity Criticality
Back
How important is this entity
Card 42
Front
Risk Appetite Threshold
Back
Per entity
Card 43
Front
Compliance Requirements
Back
What regulations apply to this entity
Card 44
Front
Entity Status
Back
Active, Inactive, Draft
Card 45
Front
Entity Life Cycle
Back
From creation to retirement
Card 46
Front
Inherited Controls
Back
Parent entity controls apply to children
Card 47
Front
Inherited Risks
Back
Parent entity risks apply to children
Card 48
Front
Entity Class Rules
Back
Automate assignment of controls, policies to entities
Card 49
Front
Automated Control Assignment
Back
Based on entity attributes
Card 50
Front
Risk Roll-up
Back
Child entity risks aggregate to parent
Card 51
Front
Control Roll-up
Back
Child entity control compliance aggregates to parent
Card 52
Front
Entity Scoping Form
Back
UI to define entity attributes and relationships
Card 53
Front
Data Certification for Entities
Back
Verify entity data accuracy
Card 54
Front
Entity Tags
Back
Keywords for grouping, searching entities
Card 55
Front
Scoping Questions
Back
What to include, what to exclude
Card 56
Front
Manual Scoping
Back
Direct selection of entities
Card 57
Front
Dynamic Scoping
Back
Rules-based selection
Card 58
Front
Entity Classification
Back
Categorizing entities based on type, criticality, function
Card 59
Front
Profile Group
Back
Collection of profiles/entities
Card 60
Front
Default Profile Type
Back
Fallback if no specific type assigned
Card 61
Front
Profile Template
Back
Pre-configured settings for new entities
Card 62
Front
Entity Scoping
Back
What needs GRC?
Card 63
Front
Entity Type
Back
Template for similar entities
Card 64
Front
Entity Class
Back
High-level grouping
Card 65
Front
Hierarchy of Entities
Back
Parent-child relationships
Card 66
Front
Manual Entity Creation
Back
For unique things
Card 67
Front
Automated Entity Creation
Back
From CMDB
Card 68
Front
CMDB Integration for Entities
Back
CI data becomes entity data
Card 69
Front
Attributes for Entities
Back
Data fields
Card 70
Front
Entity Filter
Back
Target specific entities for assessments, policies
Card 71
Front
Risk Statement Scoping
Back
Which risks apply to which entities
Card 72
Front
Control Scoping
Back
Which controls apply to which entities
Card 73
Front
Policy Scoping
Back
Which policies apply to which entities
Card 74
Front
Profile Type
Back
Another name for Entity Type
Card 75
Front
Profile Class
Back
Another name for Entity Class
Card 76
Front
Dependent Entities
Back
If this fails, what else breaks?
Card 77
Front
Relationship Editor
Back
Map dependencies between entities
Card 78
Front
Entity Owner
Back
Who's accountable for this entity
Card 79
Front
Entity Criticality
Back
How important is this entity
Card 80
Front
Risk Appetite Threshold
Back
Per entity
Card 81
Front
Compliance Requirements
Back
What regulations apply to this entity
Card 82
Front
Entity Status
Back
Active, Inactive, Draft
Card 83
Front
Entity Life Cycle
Back
From creation to retirement
Card 84
Front
Inherited Controls
Back
Parent entity controls apply to children
Card 85
Front
Inherited Risks
Back
Parent entity risks apply to children
Card 86
Front
Entity Class Rules
Back
Automate assignment of controls, policies to entities
Card 87
Front
Automated Control Assignment
Back
Based on entity attributes
Card 88
Front
Risk Roll-up
Back
Child entity risks aggregate to parent
Card 89
Front
Control Roll-up
Back
Child entity control compliance aggregates to parent
Card 90
Front
Entity Scoping Form
Back
UI to define entity attributes and relationships
Card 91
Front
Data Certification for Entities
Back
Verify entity data accuracy
Card 92
Front
Entity Tags
Back
Keywords for grouping, searching entities
Card 93
Front
Scoping Questions
Back
What to include, what to exclude
Card 94
Front
Manual Scoping
Back
Direct selection of entities
Card 95
Front
Dynamic Scoping
Back
Rules-based selection
Card 96
Front
Entity Classification
Back
Categorizing entities based on type, criticality, function
Card 97
Front
Profile Group
Back
Collection of profiles/entities
Card 98
Front
Default Profile Type
Back
Fallback if no specific type assigned
Card 99
Front
Profile Template
Back
Pre-configured settings for new entities
Card 100
Front
Entity Scoping
Back
What needs GRC?
Card 101
Front
Entity Type
Back
Template for similar entities
Card 102
Front
Entity Class
Back
High-level grouping
Card 103
Front
Hierarchy of Entities
Back
Parent-child relationships
Card 104
Front
Manual Entity Creation
Back
For unique things
Card 105
Front
Automated Entity Creation
Back
From CMDB
Card 106
Front
CMDB Integration for Entities
Back
CI data becomes entity data
Card 107
Front
Attributes for Entities
Back
Data fields
Card 108
Front
Entity Filter
Back
Target specific entities for assessments, policies
Card 109
Front
Risk Statement Scoping
Back
Which risks apply to which entities
Card 110
Front
Control Scoping
Back
Which controls apply to which entities
Card 111
Front
Policy Scoping
Back
Which policies apply to which entities
Card 112
Front
Profile Type
Back
Another name for Entity Type
Card 113
Front
Profile Class
Back
Another name for Entity Class
Card 114
Front
Dependent Entities
Back
If this fails, what else breaks?
Card 115
Front
Relationship Editor
Back
Map dependencies between entities
Card 116
Front
Entity Owner
Back
Who's accountable for this entity
Card 117
Front
Entity Criticality
Back
How important is this entity
Card 118
Front
Risk Appetite Threshold
Back
Per entity
Card 119
Front
Compliance Requirements
Back
What regulations apply to this entity
Card 120
Front
Entity Status
Back
Active, Inactive, Draft
Card 121
Front
Entity Life Cycle
Back
From creation to retirement
Card 122
Front
Inherited Controls
Back
Parent entity controls apply to children
Card 123
Front
Inherited Risks
Back
Parent entity risks apply to children
Card 124
Front
Entity Class Rules
Back
Automate assignment of controls, policies to entities
Card 125
Front
Automated Control Assignment
Back
Based on entity attributes
Card 126
Front
Risk Roll-up
Back
Child entity risks aggregate to parent
Card 127
Front
Control Roll-up
Back
Child entity control compliance aggregates to parent
Card 128
Front
Entity Scoping Form
Back
UI to define entity attributes and relationships
Card 129
Front
Data Certification for Entities
Back
Verify entity data accuracy
Card 130
Front
Entity Tags
Back
Keywords for grouping, searching entities
Card 131
Front
Scoping Questions
Back
What to include, what to exclude
Card 132
Front
Manual Scoping
Back
Direct selection of entities
Card 133
Front
Dynamic Scoping
Back
Rules-based selection
Card 134
Front
Entity Classification
Back
Categorizing entities based on type, criticality, function
Card 135
Front
Profile Group
Back
Collection of profiles/entities
Card 136
Front
Default Profile Type
Back
Fallback if no specific type assigned
Card 137
Front
GRC Workbench
Back
Centralized view
Card 138
Front
Continuous Monitoring
Back
Automate control testing
Card 139
Front
Indicators
Back
Data points
Card 140
Front
Automated Indicators
Back
Scripted checks
Card 141
Front
Manual Indicators
Back
Human verification
Card 142
Front
Indicator Templates
Back
Pre-defined checks
Card 143
Front
Remediation Tasks
Back
Created from failed indicators
Card 144
Front
Audit Engagement stages
Back
Plan, fieldwork, report, respond
Card 145
Front
Audit Workbench
Back
Manage engagements
Card 146
Front
Audit Planning
Back
Define scope, objectives, resources
Card 147
Front
Audit Fieldwork
Back
Gather evidence
Card 148
Front
Audit Findings
Back
Identified issues
Card 149
Front
Audit Report
Back
Summary of findings, recommendations
Card 150
Front
Response & Follow-up
Back
Management actions