Domain 1 of 4 · Chapter 2 of 2

Architect for Governance, Risk, and Compliance

Unlock the complete study guide + 1,500 practice questions across 12 full exams.

Bundled into the existing Information Systems Security Architecture Professional premium course — no separate purchase.

14-day money-back guarantee — no questions asked.

Included in this chapter:

  • The GRC operating model
  • Key assets, business objectives, and stakeholders
  • Risk assessment artifacts
  • From treatment advice to authorization
  • Designing for auditability
  • Designing monitoring and reporting
  • From scan finding to verified patch
  • Establishing and recording control status
  • How this objective is tested

The four risk treatment options compared

AspectAvoidMitigateTransfer or shareAccept
What the decision changesThe activity or condition creating the exposure stops or is redesignedLikelihood, impact, or both, through added safeguardsWho bears specified financial or operational consequencesNothing about the exposure itself
Exposure afterwardsThe identified exposure no longer existsReduced residual risk remains and is trackedThe event still occurs and unallocated consequences remainResidual risk is retained in full, within tolerance
Typical instrumentWithdrawing, rejecting, or redesigning the activityControls that prevent, limit harm, improve detection, or speed recoveryContracts, insurance, and service arrangementsA documented decision with rationale, authority, and review point
What the architect suppliesEvidence that the exposure is inherent to the activityWhich risk component each proposed control movesWhich consequences the arrangement does not transferThe current residual risk and the assessment it rests on
Frequent misreadReducing risk with controls is mitigation; eliminating its source is avoidanceInsurance is not mitigation, because the event still happensLegal accountability and reputational harm rarely transferInaction or an unfunded fix can amount to implicit acceptance, even though clear recording and communication are preferable

Decision tree

Is the activity itself required by the mission? No, it can stop Avoid exposure ceases to exist Yes Can safeguards move likelihood or impact? Yes, within cost Mitigate residual risk remains, tracked No, or not enough Can consequences be contracted to another party? Yes, specified ones Transfer or share accountability stays in house No Accept only within tolerance Every branch ends the same way the official with risk authority decides and records it

Cheat sheet

  • Asset inventory must include resources and dependencies that support mission outcomes
  • Business owners determine mission criticality and acceptable impact
  • Information owners govern classification and handling requirements
  • GRC roles must assign decision rights as well as responsibilities
  • Current and Target Profiles turn objectives into prioritized posture gaps
  • DPO applicability follows authority, monitoring, and sensitive-data scale
  • A continuous monitoring strategy is grounded in organizational risk tolerance
  • Monitoring metrics must support defined risk decisions
  • Risk reporting must be tailored to each decision-making tier
  • Automated monitoring complements rather than replaces procedural assessment
  • Monitoring findings must feed response and strategy updates
  • Vulnerability management coverage depends on an authoritative asset inventory
  • Vulnerability priority combines technical severity with exploit and mission context
  • Enterprise patch management ends with installation verification
  • Control assessments use examine, interview, and test methods to obtain objective evidence
  • A remediation plan tracks an unresolved weakness rather than closing it
  • Audit events must support reconstruction and individual accountability
  • Consistent authoritative time enables reliable event correlation
  • Audit records require protection from the subjects they monitor
  • Audit retention follows legal, regulatory, forensic, and business evidence needs
  • Forensic evidence requires preserved integrity and documented chain of custody
  • Audit responsibilities must separate incompatible duties
  • Assurance rigor must match impact and required confidence
  • Risk assessment preparation fixes purpose, scope, assumptions, sources, and method
  • A threat source is distinct from the event it may initiate
  • Predisposing conditions shape susceptibility even when they are not flaws
  • Likelihood reflects threat, susceptibility, and existing safeguards
  • Risk determination combines likelihood with the magnitude of impact
  • Risk treatment is selected against approved risk tolerance
  • Risk mitigation reduces likelihood, impact, or both through safeguards
  • Risk avoidance removes the activity or condition creating exposure
  • Risk transfer reallocates consequences but does not eliminate all risk
  • Risk acceptance requires an informed decision by authorized ownership
  • Risk treatment follows scenario evaluation rather than control availability
  • Control assessment informs but does not grant system authorization

Unlock with Premium — includes all practice exams and the complete study guide.

Also tested in

References

  1. The NIST Cybersecurity Framework (CSF) 2.0 Whitepaper
  2. NIST SP 800-30 Rev. 1, Guide for Conducting Risk Assessments Whitepaper
  3. NIST SP 800-37 Rev. 2, Risk Management Framework for Information Systems and Organizations Whitepaper
  4. NIST SP 800-92, Guide to Computer Security Log Management Whitepaper
  5. NIST SP 800-53 Rev. 5, Security and Privacy Controls for Information Systems and Organizations Whitepaper
  6. NIST SP 800-86, Guide to Integrating Forensic Techniques into Incident Response Whitepaper
  7. NIST SP 800-137, Information Security Continuous Monitoring (ISCM) for Federal Information Systems and Organizations Whitepaper
  8. NIST SP 800-40 Rev. 4, Guide to Enterprise Patch Management Planning: Preventive Maintenance for Technology Whitepaper
  9. NIST SP 800-53A Rev. 5, Assessing Security and Privacy Controls in Information Systems and Organizations Whitepaper