Topic module

Governance, Risk, Compliance and Third-Party Oversight

Security program questions test policies, standards, risk registers, risk responses, compliance obligations, vendor assessment, contracts, and shared responsibility.

Long-form learning
Concept to Risk to Memory to Check-up

How to study for Security+

Treat each item as a control-selection problem: identify the asset, threat, vulnerability, control objective, operational context, and risk tradeoff.

Core concepts

Concept 1

Governance sets direction, accountability, decision rights, policies, and oversight for security risk.

Exam cue: Separate policy, standard, procedure, and guideline.

Concept 2

Risk management identifies, analyzes, treats, monitors, and reports risk using business context.

Exam cue: Choose avoid, transfer, mitigate, or accept based on business decision.

Concept 3

Third-party risk management evaluates vendors before and during the relationship through due diligence, contracts, monitoring, and offboarding.

Exam cue: Evaluate vendors before granting access to sensitive systems or data.

Risk pitfalls and guardrails

Accepting risk without an accountable owner.

Guardrail: Avoid answers that trust location alone, skip evidence, ignore business impact, or choose a tool that does not address the described risk.

Confusing compliance with complete security.

Guardrail: Avoid answers that trust location alone, skip evidence, ignore business impact, or choose a tool that does not address the described risk.

Skipping vendor review because a contract is already signed.

Guardrail: Avoid answers that trust location alone, skip evidence, ignore business impact, or choose a tool that does not address the described risk.

Memory anchors

Policy

A policy states management intent and required behavior at a high level.

Standard

A standard defines mandatory details needed to comply with a policy.

Procedure

A procedure gives step-by-step instructions for performing a required task.

Guideline

A guideline gives recommended practice that may allow flexibility.

Risk Register

A risk register records risks, owners, likelihood, impact, response, and status.

Risk Acceptance

Risk acceptance is an accountable decision to tolerate residual risk.

Risk Transfer

Risk transfer shifts financial or operational impact through insurance or contracts.

Risk Mitigation

Risk mitigation reduces likelihood or impact through controls.

Vendor Due Diligence

Vendor due diligence evaluates a third party before sensitive access or reliance.

SLA

A service-level agreement defines expected service performance, responsibilities, and remedies.

Checkpoint rule

Do the check-up only after you can summarize each concept in one sentence and identify one dangerous pitfall from memory.

Knowledge Check (after reading)

Short check-up to confirm understanding of this module.

Check-up Questions

1-2 question checkpoint

The board states that sensitive data must be protected according to business and legal requirements. What type of document is this high-level management direction?

A document requires AES-256 for a defined class of stored data and TLS 1.2 or later in transit. What type of document is it?

Answer all questions to submit.

Next step personalized recommendations

What is Pass Harbor?

Completely free exam prep for 317 U.S. exams.

  • Practice questions
  • Flashcards
  • Study guides
  • Mock exams
  • No registration
  • No paywall
  • Start instantly
No more expensive exam prep. Quality study tools should be accessible to everyone.