Policy and Compliance
CIS-RC · 75 questions
- A city must adopt NIST CSF as an external mandate library in ServiceNow IRM. Where should the Policy and Compliance content lifecycle start?
- PCI DSS requirement 8.x must be tracked as a discrete obligation under the city’s adopted PCI authority document. Which record should be created next in the lifecycle?
- The city authors an internal access-control policy that must be reviewed, approved, and made active for the organization. Which lifecycle outcome is required?
- Compliance authors a reusable outcome “Restrict privileged access” intended to satisfy multiple regulatory citations. Which content-chain record expresses that reusable outcome?
- After scoping the “Restrict privileged access” control objective to the ERP entity, what lifecycle step creates the owned work item for the ERP manager?
- Quarterly control testing is due for an active ERP access control. What Policy and Compliance lifecycle activity should the owner perform?
- A control test fails for the ERP privileged-access control. What should happen next in the lifecycle?
- A clinic department requests temporary relief from MFA policy for a legacy application. How should IRM handle the request?
- A regulation is superseded and the related authority document must leave active use. What lifecycle practice is appropriate?
- After a regulatory revision, citations under an authority document are updated. What impact must compliance managers assess?
- A policy remains in draft while authors refine wording. What lifecycle gate should prevent premature obligations?
- When is a generated control typically ready for attestation and monitoring in the lifecycle?
- Remediation tasks for a failed control are marked complete. What additional lifecycle step restores confidence that the control is effective?
- Authors upload step-by-step procedure documents that support an internal access policy. How do these differ from authority citations in the content model?
- Leadership worries policies will silently go stale over multi-year cycles. What lifecycle planning should the compliance team include?
- A county privacy office loads a new state privacy citation and finds an existing control objective already covers the same access-review requirement. What should the compliance lead do?
- Examiners ask a municipal utility for prior-year control test outcomes after the current test cycle opens. What must the compliance team preserve?
- After a city IT reorg mid-cycle, the group that owns a generated access-control record moves to a new service desk. How should ownership be handled?
- A hospital must remediate a broken logging system for sixty days and needs a temporary manual log review accepted by compliance. How should this be modeled in IRM?
- A transit authority wants every employee to confirm they read the acceptable-use policy. Which lifecycle approach fits this awareness need?
- A county decommissions a legacy permitting application that still has generated controls sitting in active testing queues. What should happen next?
- A civic IRM rollout has an authority document, citations, control objectives, generated controls, and open issues—but failed tests never create those issues. Which stage is missing in the chain?
- One quarterly access-review control must satisfy ISO, a state privacy citation, and an internal policy. What architecture should the city implement?
- Architects ask how authority documents and internal policies connect in ServiceNow Policy and Compliance. What is the architectural hinge?
- A new analyst treats every control objective as if it were already an entity-specific control. Why is that incorrect?
- Evidence from one access-review test must support several mapped regulatory citations. What architecture enables that?
- A utility publishes control objectives for encryption but never scopes them to entities. What happens architecturally?
- A consultant proposes a separate ‘compliance-only CMDB’ so IRM never touches the enterprise CMDB. What should the implementation lead answer?
- Overlapping regulations force a city to invent near-duplicate control objectives for every new mandate. How do common-controls style content packs help?
- A control requires a manager’s judgment that segregation of duties remains appropriate, while another control can be measured by an automated configuration check. How should evidence architecture differ?
- Several control tests fail across departments in a state agency. Where should remediation converge architecturally?
- A department obtains a policy exception for an unmet encryption control. What must the architecture prevent?
- Leadership wants compliance status both by business entity and by authority document. What does the data model need?
- In a workspace a record still shows older ‘policy statement’ language while docs say ‘control objective.’ What should implementers focus on architecturally?
- A large ISO-style framework needs nested clause references under one authority document. What citation structure should the team allow?
- Generated controls for a water utility appear with blank owners and nobody responds to failed tests. What accountability architecture is missing?
- A health department can auto-check encryption settings daily but still needs annual human review of exception handling. Which architecture fits?
- One control objective for backup verification is scoped to five clinic entities. What must generation create?
- Executives want a compliance scorecard for each department. What should be the system of record for those percentages?
- A city wants its internal information-security policy to demonstrate alignment to several external regulations without rewriting the policy once per regulator. What crosswalk approach should it use?
- A tax authority maps SOX, NIST, and local statute citations to one privileged-access control objective for the tax system. What should the compliance implementer configure?
- A hospital GRC lead wants generated access-review controls to appear only on applications classified as Critical Applications. How should the control objective be scoped?
- An EHR application must have access-review control tests run every three months. What frequency setting should the compliance admin configure on the control?
- Generated access-review controls for the EHR need a named owner accountable for testing and remediation. Whom should the implementer assign as control owner?
- Application owners must confirm that backup restore tests occurred this period. Which Policy and Compliance configuration supports that verification pattern?
- A privacy program needs hundreds of framework citations loaded quickly rather than typed by hand. What should the IRM implementer use?
- Policy exceptions longer than 30 days must go through formal approval before remaining active. What should the compliance admin configure?
- The information-security policy record should show which control objectives implement its requirements. What relationship should the implementer establish?
- PCI-sensitive entities require testers to attach supporting files when completing control tests. What should be configured?
- Several entities were decommissioned, but historical control test results must remain. How should active testing be handled?
- Utility SCADA entity control tests must alert owners when they become overdue. What should the implementer configure?
- Storage configuration items should show automated pass/fail for encryption at rest without waiting for a manual tester. What should be set up?
- Failed compliance tests for an entity should open issues that land with the team that supports that entity. What configuration achieves this?
- Court IT wants a compliance workspace focused only on controls for the e-filing entity. What should the admin establish?
- A new state privacy citation requires encryption, and an encryption control objective already exists. What is the preferred mapping approach?
- Before an information-security policy can publish, Legal and IT Security must approve. What should be configured?
- Lab clone entities must not receive the same generated production controls. How should generation be constrained?
- When remediation closes a compliance issue, testers should automatically receive a follow-up verification task. What should be configured?
- Examiners ask how each mapped citation is satisfied by the control design. What should compliance configure for traceability?
- Finance shared services needs coordinated year-end testing across many controls at once. What should the compliance lead configure?
- A passed access-review control test needs durable proof for later review. What supporting process should the tester follow?
- Failed controls produced many open issues; some may miss dates and need formal risk acceptance. How should the backlog be managed?
- Remediations for public-facing portals are overdue and need executive visibility. What supporting process should compliance use?
- Examiners request a file showing how payments-environment citations map to controls. What should compliance provide?
- Every department must complete annual acknowledgment of key policies. What organization-wide supporting process should compliance run?
- A county IRM lead discovers several compensating controls that have quietly become permanent workarounds for open policy exceptions. What should the compliance team validate first?
- A municipal utility's control test fails because server hardening drifted from the approved baseline. How should Policy and Compliance coordinate with ITSM without turning CIS-RC into a Change Management exam?
- Between scheduled control tests, a hospital's continuous indicator shows repeated access-review breaches on a clinical application. What should happen in compliance?
- A transit authority's attestation campaign returns dozens of identical 'yes' responses submitted within minutes. What quality-review action should compliance take?
- A state agency's external audit fieldwork starts next month, but control evidence is still scattered across email. What calendar practice should Policy and Compliance adopt?
- A new privacy regulation adds obligations that do not map cleanly to the city's current citation library. What should the compliance content team do first?
- A county GRC steering committee asks for operational health of the compliance program, not a list of policy PDFs. Which KPI set best fits?
- The same access-control fails for a fourth quarter in a row at a public hospital, and remediation keeps slipping. What supporting handoff should compliance make?
- Three different testers evaluate the same encryption control at a water utility and produce inconsistent procedures and evidence. What should compliance maintain?
- Entity owners at a regional school district ignore long email threads about overdue attestations and open issues. How should compliance close the loop?