Architect for Governance, Risk, and Compliance
Unlock the complete study guide + 1,500 practice questions across 12 full exams.
Bundled into the existing Information Systems Security Architecture Professional premium course — no separate purchase.
14-day money-back guarantee — no questions asked.
Included in this chapter:
- The GRC operating model
- Key assets, business objectives, and stakeholders
- Risk assessment artifacts
- From treatment advice to authorization
- Designing for auditability
- Designing monitoring and reporting
- From scan finding to verified patch
- Establishing and recording control status
- How this objective is tested
The four risk treatment options compared
| Aspect | Avoid | Mitigate | Transfer or share | Accept |
|---|---|---|---|---|
| What the decision changes | The activity or condition creating the exposure stops or is redesigned | Likelihood, impact, or both, through added safeguards | Who bears specified financial or operational consequences | Nothing about the exposure itself |
| Exposure afterwards | The identified exposure no longer exists | Reduced residual risk remains and is tracked | The event still occurs and unallocated consequences remain | Residual risk is retained in full, within tolerance |
| Typical instrument | Withdrawing, rejecting, or redesigning the activity | Controls that prevent, limit harm, improve detection, or speed recovery | Contracts, insurance, and service arrangements | A documented decision with rationale, authority, and review point |
| What the architect supplies | Evidence that the exposure is inherent to the activity | Which risk component each proposed control moves | Which consequences the arrangement does not transfer | The current residual risk and the assessment it rests on |
| Frequent misread | Reducing risk with controls is mitigation; eliminating its source is avoidance | Insurance is not mitigation, because the event still happens | Legal accountability and reputational harm rarely transfer | Inaction or an unfunded fix can amount to implicit acceptance, even though clear recording and communication are preferable |
Decision tree
Cheat sheet
Unlock with Premium — includes all practice exams and the complete study guide.
Also tested in
References
- The NIST Cybersecurity Framework (CSF) 2.0 Whitepaper
- NIST SP 800-30 Rev. 1, Guide for Conducting Risk Assessments Whitepaper
- NIST SP 800-37 Rev. 2, Risk Management Framework for Information Systems and Organizations Whitepaper
- NIST SP 800-92, Guide to Computer Security Log Management Whitepaper
- NIST SP 800-53 Rev. 5, Security and Privacy Controls for Information Systems and Organizations Whitepaper
- NIST SP 800-86, Guide to Integrating Forensic Techniques into Incident Response Whitepaper
- NIST SP 800-137, Information Security Continuous Monitoring (ISCM) for Federal Information Systems and Organizations Whitepaper
- NIST SP 800-40 Rev. 4, Guide to Enterprise Patch Management Planning: Preventive Maintenance for Technology Whitepaper
- NIST SP 800-53A Rev. 5, Assessing Security and Privacy Controls in Information Systems and Organizations Whitepaper