certslothcertsloth
CCSP/Topic 10

ISC2 / Professional

Governance, Risk and Assurance

2 min read5 recall promptsReviewed 2026-10-10

Memory hook: Business owns risk; controls reduce it; evidence checks it.

Must remember

Policy states management intent; standards set mandatory requirements; procedures describe steps; guidelines advise. Assign data/system owners and accountable decision makers. Security should enable business objectives within legal and risk constraints.

Threats can exploit vulnerabilities and cause impact. Inherent risk exists before controls; residual risk remains afterward. Appetite is the broad willingness to take risk; tolerance defines acceptable variation/bounds. Treat risk by avoiding, mitigating, transferring/sharing or formally accepting it. Insurance transfers some financial consequences, not accountability or every impact.

Quantitative example: an asset worth $100,000 with 20% expected loss per event has SLE = $20,000. At 0.5 events/year, ALE = $10,000/year. Estimates are uncertain; qualitative matrices express relative likelihood/impact without pretending to precise currency.

Change control records purpose, impact, dependencies, approvals, testing, maintenance window, rollback and validation. Emergency changes still need defined authority and retrospective documentation. Version control supports traceability; it does not approve a change by itself.

Supplier assessment covers security evidence, subcontractors, data location, access, continuity, breach notification and exit/deletion terms. SLAs define service commitments; NDAs protect shared confidential information; rules of engagement constrain testing. Review suppliers throughout the relationship.

Audits compare evidence against criteria; assessments evaluate controls; attestation is a formal assertion/report; penetration tests validate selected attack paths. Compliance is a baseline tied to scope, not proof of complete security. Awareness programs need role-specific training, usable reporting channels and measured outcomes, not only annual attendance.

Choose under exam pressure

Requirement Choice and reason
Control costs more than justified risk reduction Escalate a documented business risk decision.
Supplier stores sensitive customer data Assess contractual, technical and lifecycle controls.
Audit finds missing evidence Correct the evidence/control process, not merely the report wording.

Traps

  • A technical administrator does not unilaterally accept business risk.
  • A supplier certification applies to its stated scope and period.

Active recall

1. What is residual risk?

Risk remaining after controls and treatment.

2. Calculate ALE from SLE $20,000 and ARO 0.5.

$10,000 per year as an estimate.

3. Policy versus procedure?

Policy sets intent; procedure specifies steps.

4. Does buying insurance remove accountability?

No. It can transfer specified financial consequences, not all duties or harms.

5. Why define rollback before a change?

To recover predictably if validation fails rather than improvise during an outage.

Sources

CLOSE THE NOTES. EXPLAIN THE CHOICE.

How well could you recall it?

Your next review is based on this answer. Progress stays in this browser.

Search across every published topic.