CIS – Risk and Compliance flashcards

SERVICENOW · CIS – Risk and Compliance (CIS-RC)

By caffeinated soul

Log in to rate

Flash cards I used when studying for SN GRC. Hope it helps.

Certification Summary

The ServiceNow Certified Implementation Specialist - Risk and Compliance exam targets consultants tasked with building and configuring the GRC suite, rather than those who simply navigate the interface. Most people take this because a partner status requires a specific number of certified bodies, so expect questions that assume you know how to map control objectives to entities without breaking the underlying table structure.

Expect the exam to focus on Entity Scoping, Policy and Compliance, and Risk Implementation, which account for 75 percent of the content. The remaining sections cover GRC Overview, Implementation Planning, Audit Management, and Extended Capabilities. You will need to demonstrate how to configure the relationship between control tests and audit engagements within the GRC module.

Study

Card 1 of 150

Log in to mark cards as mastered and track progress.

The Imposter Hunt

The Imposter Hunt (Unlocked!)

Prove your knowledge to unlock this challenge.

Test your knowledge and spot the fake definitions.

0% / 75% mastery
0%

Mastery

0 of 150 cards mastered

All cards (150)

Scroll to review fronts and backs

Card 1

Front

GRC

Back

Governance, Risk, Compliance

Card 2

Front

Risk appetite

Back

How much risk we'll take to hit goals

Card 3

Front

Risk tolerance

Back

Acceptable variance from risk appetite

Card 4

Front

Control vs Policy

Back

Control = action to manage risk

Card 5

Front

Compliance

Back

Meeting external regs, internal policies

Card 6

Front

Risk framework

Back

Structured approach to identify, assess, respond to risk

Card 7

Front

Issue

Back

Something's not right

Card 8

Front

Control objective

Back

What a control aims to achieve

Card 9

Front

Attestation

Back

Proof a control is working

Card 10

Front

Audit engagement

Back

Planned review of controls

Card 11

Front

Key Risk Indicator KRI

Back

Metric showing increasing risk exposure

Card 12

Front

Key Performance Indicator KPI

Back

Metric showing how well objectives are met

Card 13

Front

Authority document

Back

Law, regulation, standard

Card 14

Front

Continuous monitoring

Back

Automated checks for control performance

Card 15

Front

Control owner

Back

Person responsible for a control's effectiveness

Card 16

Front

Implementation Planning

Back

Get the requirements right

Card 17

Front

Requirements gathering

Back

Talk to the business

Card 18

Front

Phased approach

Back

Start small

Card 19

Front

MVP

Back

Minimum Viable Product

Card 20

Front

Stakeholder identification

Back

Who cares?

Card 21

Front

Data migration strategy

Back

Old data into new system

Card 22

Front

Integration points

Back

Where does this talk to other systems?

Card 23

Front

Testing plan

Back

Prove it works

Card 24

Front

Entity Scoping

Back

What needs GRC?

Card 25

Front

Entity Type

Back

Template for similar entities

Card 26

Front

Entity Class

Back

High-level grouping

Card 27

Front

Hierarchy of Entities

Back

Parent-child relationships

Card 28

Front

Manual Entity Creation

Back

For unique things

Card 29

Front

Automated Entity Creation

Back

From CMDB

Card 30

Front

CMDB Integration for Entities

Back

CI data becomes entity data

Card 31

Front

Attributes for Entities

Back

Data fields

Card 32

Front

Entity Filter

Back

Target specific entities for assessments, policies

Card 33

Front

Risk Statement Scoping

Back

Which risks apply to which entities

Card 34

Front

Control Scoping

Back

Which controls apply to which entities

Card 35

Front

Policy Scoping

Back

Which policies apply to which entities

Card 36

Front

Profile Type

Back

Another name for Entity Type

Card 37

Front

Profile Class

Back

Another name for Entity Class

Card 38

Front

Dependent Entities

Back

If this fails, what else breaks?

Card 39

Front

Relationship Editor

Back

Map dependencies between entities

Card 40

Front

Entity Owner

Back

Who's accountable for this entity

Card 41

Front

Entity Criticality

Back

How important is this entity

Card 42

Front

Risk Appetite Threshold

Back

Per entity

Card 43

Front

Compliance Requirements

Back

What regulations apply to this entity

Card 44

Front

Entity Status

Back

Active, Inactive, Draft

Card 45

Front

Entity Life Cycle

Back

From creation to retirement

Card 46

Front

Inherited Controls

Back

Parent entity controls apply to children

Card 47

Front

Inherited Risks

Back

Parent entity risks apply to children

Card 48

Front

Entity Class Rules

Back

Automate assignment of controls, policies to entities

Card 49

Front

Automated Control Assignment

Back

Based on entity attributes

Card 50

Front

Risk Roll-up

Back

Child entity risks aggregate to parent

Card 51

Front

Control Roll-up

Back

Child entity control compliance aggregates to parent

Card 52

Front

Entity Scoping Form

Back

UI to define entity attributes and relationships

Card 53

Front

Data Certification for Entities

Back

Verify entity data accuracy

Card 54

Front

Entity Tags

Back

Keywords for grouping, searching entities

Card 55

Front

Scoping Questions

Back

What to include, what to exclude

Card 56

Front

Manual Scoping

Back

Direct selection of entities

Card 57

Front

Dynamic Scoping

Back

Rules-based selection

Card 58

Front

Entity Classification

Back

Categorizing entities based on type, criticality, function

Card 59

Front

Profile Group

Back

Collection of profiles/entities

Card 60

Front

Default Profile Type

Back

Fallback if no specific type assigned

Card 61

Front

Profile Template

Back

Pre-configured settings for new entities

Card 62

Front

Entity Scoping

Back

What needs GRC?

Card 63

Front

Entity Type

Back

Template for similar entities

Card 64

Front

Entity Class

Back

High-level grouping

Card 65

Front

Hierarchy of Entities

Back

Parent-child relationships

Card 66

Front

Manual Entity Creation

Back

For unique things

Card 67

Front

Automated Entity Creation

Back

From CMDB

Card 68

Front

CMDB Integration for Entities

Back

CI data becomes entity data

Card 69

Front

Attributes for Entities

Back

Data fields

Card 70

Front

Entity Filter

Back

Target specific entities for assessments, policies

Card 71

Front

Risk Statement Scoping

Back

Which risks apply to which entities

Card 72

Front

Control Scoping

Back

Which controls apply to which entities

Card 73

Front

Policy Scoping

Back

Which policies apply to which entities

Card 74

Front

Profile Type

Back

Another name for Entity Type

Card 75

Front

Profile Class

Back

Another name for Entity Class

Card 76

Front

Dependent Entities

Back

If this fails, what else breaks?

Card 77

Front

Relationship Editor

Back

Map dependencies between entities

Card 78

Front

Entity Owner

Back

Who's accountable for this entity

Card 79

Front

Entity Criticality

Back

How important is this entity

Card 80

Front

Risk Appetite Threshold

Back

Per entity

Card 81

Front

Compliance Requirements

Back

What regulations apply to this entity

Card 82

Front

Entity Status

Back

Active, Inactive, Draft

Card 83

Front

Entity Life Cycle

Back

From creation to retirement

Card 84

Front

Inherited Controls

Back

Parent entity controls apply to children

Card 85

Front

Inherited Risks

Back

Parent entity risks apply to children

Card 86

Front

Entity Class Rules

Back

Automate assignment of controls, policies to entities

Card 87

Front

Automated Control Assignment

Back

Based on entity attributes

Card 88

Front

Risk Roll-up

Back

Child entity risks aggregate to parent

Card 89

Front

Control Roll-up

Back

Child entity control compliance aggregates to parent

Card 90

Front

Entity Scoping Form

Back

UI to define entity attributes and relationships

Card 91

Front

Data Certification for Entities

Back

Verify entity data accuracy

Card 92

Front

Entity Tags

Back

Keywords for grouping, searching entities

Card 93

Front

Scoping Questions

Back

What to include, what to exclude

Card 94

Front

Manual Scoping

Back

Direct selection of entities

Card 95

Front

Dynamic Scoping

Back

Rules-based selection

Card 96

Front

Entity Classification

Back

Categorizing entities based on type, criticality, function

Card 97

Front

Profile Group

Back

Collection of profiles/entities

Card 98

Front

Default Profile Type

Back

Fallback if no specific type assigned

Card 99

Front

Profile Template

Back

Pre-configured settings for new entities

Card 100

Front

Entity Scoping

Back

What needs GRC?

Card 101

Front

Entity Type

Back

Template for similar entities

Card 102

Front

Entity Class

Back

High-level grouping

Card 103

Front

Hierarchy of Entities

Back

Parent-child relationships

Card 104

Front

Manual Entity Creation

Back

For unique things

Card 105

Front

Automated Entity Creation

Back

From CMDB

Card 106

Front

CMDB Integration for Entities

Back

CI data becomes entity data

Card 107

Front

Attributes for Entities

Back

Data fields

Card 108

Front

Entity Filter

Back

Target specific entities for assessments, policies

Card 109

Front

Risk Statement Scoping

Back

Which risks apply to which entities

Card 110

Front

Control Scoping

Back

Which controls apply to which entities

Card 111

Front

Policy Scoping

Back

Which policies apply to which entities

Card 112

Front

Profile Type

Back

Another name for Entity Type

Card 113

Front

Profile Class

Back

Another name for Entity Class

Card 114

Front

Dependent Entities

Back

If this fails, what else breaks?

Card 115

Front

Relationship Editor

Back

Map dependencies between entities

Card 116

Front

Entity Owner

Back

Who's accountable for this entity

Card 117

Front

Entity Criticality

Back

How important is this entity

Card 118

Front

Risk Appetite Threshold

Back

Per entity

Card 119

Front

Compliance Requirements

Back

What regulations apply to this entity

Card 120

Front

Entity Status

Back

Active, Inactive, Draft

Card 121

Front

Entity Life Cycle

Back

From creation to retirement

Card 122

Front

Inherited Controls

Back

Parent entity controls apply to children

Card 123

Front

Inherited Risks

Back

Parent entity risks apply to children

Card 124

Front

Entity Class Rules

Back

Automate assignment of controls, policies to entities

Card 125

Front

Automated Control Assignment

Back

Based on entity attributes

Card 126

Front

Risk Roll-up

Back

Child entity risks aggregate to parent

Card 127

Front

Control Roll-up

Back

Child entity control compliance aggregates to parent

Card 128

Front

Entity Scoping Form

Back

UI to define entity attributes and relationships

Card 129

Front

Data Certification for Entities

Back

Verify entity data accuracy

Card 130

Front

Entity Tags

Back

Keywords for grouping, searching entities

Card 131

Front

Scoping Questions

Back

What to include, what to exclude

Card 132

Front

Manual Scoping

Back

Direct selection of entities

Card 133

Front

Dynamic Scoping

Back

Rules-based selection

Card 134

Front

Entity Classification

Back

Categorizing entities based on type, criticality, function

Card 135

Front

Profile Group

Back

Collection of profiles/entities

Card 136

Front

Default Profile Type

Back

Fallback if no specific type assigned

Card 137

Front

GRC Workbench

Back

Centralized view

Card 138

Front

Continuous Monitoring

Back

Automate control testing

Card 139

Front

Indicators

Back

Data points

Card 140

Front

Automated Indicators

Back

Scripted checks

Card 141

Front

Manual Indicators

Back

Human verification

Card 142

Front

Indicator Templates

Back

Pre-defined checks

Card 143

Front

Remediation Tasks

Back

Created from failed indicators

Card 144

Front

Audit Engagement stages

Back

Plan, fieldwork, report, respond

Card 145

Front

Audit Workbench

Back

Manage engagements

Card 146

Front

Audit Planning

Back

Define scope, objectives, resources

Card 147

Front

Audit Fieldwork

Back

Gather evidence

Card 148

Front

Audit Findings

Back

Identified issues

Card 149

Front

Audit Report

Back

Summary of findings, recommendations

Card 150

Front

Response & Follow-up

Back

Management actions