Entity Framework
CIS-RC · 60 questions
- A compliance lead scopes a statewide privacy policy to every configuration item in the CMDB, including printers and unused lab PCs. What is the main problem with that entity scope?
- A city risk team scopes ransomware exposure only to one forgotten departmental Access database. Critical 911 and utility billing applications are left out. What coverage problem does that create?
- Leadership asks “what are we governing?” before loading ISO control citations into ServiceNow IRM. What should the implementation team establish first?
- A municipality wants vendors, facilities, and business services all in year-one IRM scope without ranking which populations matter most. What approach should the team recommend?
- After a city reorg, half the departments marked in-scope no longer exist as active org units. What does this reveal about entity scoping?
- Internal audit asks whether entity scoping is only a compliance concept. How should the IRM lead respond?
- During a workshop, staff treat “scoping a control objective” as the same task as writing the control objective’s wording. What distinction should the implementer emphasize?
- A utility proposes dynamic scoping so newly discovered critical applications automatically enter GRC scope. Which capability does that approach rely on?
- An agency chooses purely manual entity creation for roughly 5,000 servers in scope. What should the implementer advise?
- A regulator asks which systems PCI applies to at a municipal payment processor. What should leadership point to as the durable answer?
- Two city departments argue whether a shared integration hub belongs in either department’s IRM scope. What is the soundest handling?
- Scoping workshops finish, but inclusion and exclusion choices for entity populations are never written down. What should be required next?
- A mayor demands that “everything” be scored for risk and compliance by Friday. What guidance should the IRM lead give?
- Disaster-recovery obligations cover different systems than the city’s PCI scope. How should entity scoping handle that?
- Outsourced payroll is omitted from entity scope because “it is not on our servers.” The city remains accountable for employee data protection. What correction is needed?
- An implementer creates one entity type with no table filter, so generation pulls every record from a very large table. What is wrong with that design?
- Critical applications should become IRM entities from application CIs where business criticality is high. Which configuration pattern matches that need?
- Departments must be represented as entities using existing organizational data. What entity-type approach should the team take?
- A water utility must govern treatment plants and depots as well as IT applications. How should entity types be structured?
- Admins create an entity type for critical applications but never run generation or refresh. No entities appear. What misconception does this expose?
- An entity-type filter depends on a transient custom field that only one administrator understands and plans to retire. What design change is appropriate?
- A proposed “vendors” entity type points at a random spreadsheet import table full of duplicate vendor names. What source choice is better?
- Two entity types use overlapping filters and both generate entities for the same configuration item. What problem should the team fix?
- A team wants entity types for “anything we might audit someday,” including inactive side projects with no current program. What alignment should leadership enforce?
- An applications entity type still generates entities for decommissioned CIs. What condition change should be made?
- A county IRM team proposes entity types that pull business services from CSDM-aligned service tables rather than only servers. When should the implementer accept service entities?
- An implementer clones a working entity type onto every child CMDB table 'just in case.' What approach should the IRM lead enforce instead?
- Finance process owners need 'payment processing' governed in IRM, but they reject server-level entities as meaningless to them. What entity-type approach fits?
- The city marks additional applications as business-critical in the CMDB and expects them to appear as IRM entities without hand-building each one. What should the design emphasize?
- A consultant says entity types are optional because the hospital can hand-build three EHR-related entities. How should the implementer respond for a civic-scale estate?
- Leadership wants IRM reporting rollups by Organization, Technology, and Third Party. Which construct should the implementer use to group entity types for hierarchy and reporting?
- Without entity classes, owners face a flat list of roughly 2,000 entities and cannot navigate ownership. What problem does introducing classes primarily solve?
- A utility wants scoped GRC content from a parent business-unit pattern to cascade toward child entities. What design relationship should the workshop emphasize?
- A builder tries to use entity classes as a second filter engine that duplicates entity-type table conditions. What distinction should be reinforced?
- A utility creates a new entity class for every team rename on the org chart. What taxonomy approach should the IRM architect prefer?
- Executives ask for residual risk dashboards sliced by entity class across the municipal portfolio. What must be true in the entity design?
- After a city reorg, an application entity must move from one entity class to another. How should that change be treated?
- A class-design workshop includes only CMDB admins and skips audit and risk consumers. What should the lead correct?
- Someone proposes entity classes named PCI, HIPAA, and SOX for every regulated workload. What guidance should the implementer give?
- A municipality needs parent/child links from city to department to system so ownership and rollups stay coherent. What modeling approach fits?
- A team skips the entity class approach, arguing that entity types alone are enough. What limitation should the implementer highlight?
- Under a shared Technology entity class, the city needs both application and infrastructure entity types. Is that valid?
- Controls and risks must attach to something durable in the IRM architecture. What is the architectural join point between organizational objects and GRC content?
- After associating a control objective to relevant entity types, the compliance lead expects control records on those entities. Which architecture behavior produces them?
- A risk statement is associated to hospital entity types so each in-scope entity receives a risk to assess. What parallel architecture behavior applies?
- An architecture diagram shows entities but omits the document → content → item layers, leaving the team unsure why nothing appears on entities. What distinction must be taught?
- Entity types will generate from CMDB application classes, but Discovery and ownership data are known to be stale. What architectural dependency should be called out?
- Policy, Risk, and Audit teams each need to see the same hospital EHR entity rather than three conflicting copies. What architecture principle applies?
- Attestation workflows have no assignee because ownership fields on entities are empty. What architecture requirement was missed?
- The entity hierarchy is city → department → application, and the team wants department-level scoped content to inform child applications where supported. What should the architecture emphasize?
- A municipal IRM team keeps entities in ServiceNow but a bureau proposes a parallel SharePoint list as a second master for the same governable buildings and applications. What should the architect insist on?
- CMDB and HR integrations continuously add new configuration items and org units, but GRC entities used for control scoping lag weeks behind. What should the entity architecture include?
- A county compliance program must apply policies to IT assets and to non-IT objects such as business processes and physical facilities. How should entity architecture be designed?
- An IRM admin plans a breaking redesign of entity types that already have generated controls and risks attached. What must happen before the redesign proceeds?
- A utility’s IRM reference architecture must support continuous monitoring, not only periodic questionnaires. Where should indicator hooks sit in the entity-centric model?
- Workspace UX labels objects as entities while classic tables still use older profile-oriented names. When designing architecture for a city IRM rollout, what should the answer emphasize?
- A transit agency needs blast-radius reporting that shows which applications run in which facilities when a site risk materializes. What entity-framework capability is required?
- Generating controls and risks for entities that are out of the compliance program’s agreed scope floods owners with noise. What should architecture enforce before generation?
- Why does the CIS-RC blueprint weight Entity Framework heavily relative to other domains for an IRM implementation?
- Multiple agencies keep local CMDB-like sources but must report against shared IRM entity types for a federated city program. What design approach fits?