Which word in the OCEG definition separates GRC from three functions working separately?
GRC is not a department but the property of not having three different truths about the same control.
OCEG (Open Compliance and Ethics Group) · What Is GRC (Governance, Risk, and Compliance)?
What did version 2.0 of the NIST framework change, and why is the new function placed at the centre?
Governance is not an extra heading but the function that decides how all the others are applied.
National Institute of Standards and Technology (NIST) · The NIST Cybersecurity Framework (CSF) 2.0
What is the difference between risk appetite and risk tolerance?
A risk owner is someone who can allocate budget and stop an activity, not someone who keeps a register.
National Institute of Standards and Technology (NIST) · Guide for Conducting Risk Assessments (NIST SP 800-30 Rev. 1)
What simple test shows a control is real rather than merely prepared for the audit?
The certificate is a photograph, and security is the film it was cut from.
Bruce Schneier · The Process of Security
Which line does the information security officer sit on, and why can they not give assurance?
Nobody can give independent assurance over their own work, however competent they are.
The Institute of Internal Auditors (IIA) · The IIA's Three Lines Model: An Update of the Three Lines of Defense
What does clause 9.1 of ISO/IEC 27001:2022 explicitly require, beyond the instruction to measure?
A performance indicator describes what happened, while a risk indicator moves before it happens.
William Thomson (Lord Kelvin) · Electrical Units of Measurement
What turns a statement about a control into objective evidence?
What cannot be shown to a stranger did not happen, as far as the audit is concerned.
Richard P. Feynman · Cargo Cult Science
Why is ISO/IEC 27001 a management system standard rather than a catalogue of controls?
Annex A is the consequence of the risk assessment, not the starting point of the implementation.
ISO/IEC · ISO/IEC 27001:2022 — Information security, cybersecurity and privacy protection — Information security management systems — Requirements
What must be taken into account when determining the scope, under clause 4.3?
A scope too narrow passes the audit but convinces no customer, and one too broad never gets finished.
ISO/IEC · ISO/IEC 27001:2022 — Information security, cybersecurity and privacy protection — Information security management systems — Requirements
Which two responsibilities must top management assign outright under 5.3?
Clause 5 is audited in the executive office, not in the server room.
ISO/IEC · ISO/IEC 27001:2022 — Information security, cybersecurity and privacy protection — Information security management systems — Requirements
What is the difference between risk analysis and risk evaluation?
Criteria are written before the risks, otherwise the threshold moves to fit the result.
ISO/IEC · ISO/IEC 27005:2022 — Information security, cybersecurity and privacy protection — Guidance on managing information security risks
What must the Statement of Applicability say about a necessary control that is not yet implemented?
Annex A is the safety net under your list of controls, not its source.
ISO/IEC · ISO/IEC 27001:2022 — Information security, cybersecurity and privacy protection — Information security management systems — Requirements
What does clause 6.3, new in the 2022 edition, require?
An objective that cannot be measured is an intention on letterhead.
ISO/IEC · ISO/IEC 27001:2022 — Information security, cybersecurity and privacy protection — Information security management systems — Requirements
What does ISO/IEC 27001:2022 require about outsourced processes?
Clause 6 writes the method, clause 8 proves it was used.
ISO/IEC · ISO/IEC 27001:2022 — Information security, cybersecurity and privacy protection — Information security management systems — Requirements
Why can the very person who implemented a process not audit it internally?
An audit without independence produces calm, not assurance.
ISO · ISO 19011:2026 — Guidelines for auditing management systems
What is the difference between a correction and a corrective action?
A closed ticket is not an eliminated cause.
W. Edwards Deming · Out of the Crisis
How many controls are in Annex A of ISO/IEC 27001:2022 and how are they grouped?
Annex A is a checklist, not a shopping list.
ISO/IEC · ISO/IEC 27001:2022 — Information security, cybersecurity and privacy protection — Information security management systems — Requirements
Which three columns does a useful gap analysis have?
A gap analysis without owners and deadlines is a list of regrets.
Sun Tzu, traducere Lionel Giles · The Art of War
What is checked in stage 1 and what is checked in stage 2?
Stage 1 judges the documents, stage 2 judges the evidence, and accreditation judges the body that judges both.
Ronald Reagan · Remarks on Signing the Intermediate-Range Nuclear Forces Treaty
What are the four parts of the response to a nonconformity?
A major nonconformity is closed with a root cause and a demonstrated corrective action, not with a correction.
ISO · ISO 19011:2018 — Guidelines for auditing management systems