Implementation Planning
CIS-RC · 15 questions
- A city wants Policy and Compliance, Risk, Audit, Vendor Risk, and BCM all live in ninety days for every department. What should the implementer recommend for phase one?
- A county clerk’s office needs to show SOX-like financial control testing for a shared-services ERP. Which use-case framing best fits IRM?
- A municipal hospital prioritizes clinical application risk scoring before cleaning the policy library. What foundation must still be in place for that Risk-first use case?
- A state department of transportation wants internal audit to plan engagements from a living risk register. Which use-case approach fits IRM?
- A city payments team faces PCI obligations and asks which IRM outcome should define success for phase one. Which criteria are most appropriate?
- Before any IRM configuration, a program manager skips stakeholder mapping. Which checklist action should happen first?
- The CMDB is known to be stale, yet the team wants entity types pointed at all CIs immediately. What should the implementation checklist emphasize first?
- An implementer activates every IRM-related plugin “just in case” without a checklist. What practice should replace that approach?
- A kickoff has no RACI for who approves entity class design. What should the implementation team checklist include?
- Training and change management are omitted from an IRM go-live plan. Which checklist item should be restored?
- A city grants every IT analyst the GRC admin role for convenience. What role practice should the implementer enforce instead?
- Who should own monthly control attestations for the city’s permitting system under a normal lines-of-defense model?
- A risk manager persona needs to assess and treat risks without redesigning entity types. How should roles be separated?
- Compliance manager and audit manager both want authority to close findings the same way. How should the implementer distinguish the roles?
- Department directors request visibility limited to their entities’ risks and controls. What access approach should the implementer use?