Click Study Flashcards above to open the flashcard hub — hundreds of CGRC cards you can flip, match, type, or quiz yourself on. Every card is drawn from the seven official ISC2 domains and the NIST Risk Management Framework, so you study exactly what the exam tests.[1] Pair them with our free practice test and study guide.
CGRC is one of the 9 ISC2 certifications — explore our ISC2 flashcards to compare and prep across the whole family.
CGRC Flashcard Study Modes
Flip mode lets you read a term, think, and turn the card over at your own pace. Type mode shows the definition and asks you to produce the term exactly, so a front like POA&M has to come from memory. Match is a timed term-to-definition game for speed, and Quiz turns the same cards into multiple-choice questions.

Why Flashcards Work for the CGRC
Implementation of Controls carries the heaviest official weight at 17% and holds 20 cards. These drill how controls move from paper into practice, with the SSP, SSP owner, and SP 800-18 cards covering documentation, while Implement step, Technical control, and Deterrent control fix the vocabulary of control types and phases. There is even a card front called Heaviest domain to remind you where the exam leans.
GRC & Risk Management Program is the largest block in the deck with 41 cards. It mixes program vocabulary such as GRC, Risk, and RMF with the quantitative risk terms you have to keep straight under pressure, including SLE, ARO, and ALE. Regulatory and framework fronts like GDPR and CMMC also live here, so expect broad coverage rather than one narrow topic.
Assessment/Audit of Controls holds 25 cards at 16%. The assessment method fronts Examine, Interview, and Test are the backbone, supported by SP 800-53A, and the artifact terms SCA, SAP, SAR, and POA&M that tell you who assesses, what plan is used, what report comes out, and what happens to findings.
Selection & Approval of Controls has 20 cards at 14%, built around Scoping, Tailoring, and Overlay plus the baseline references SP 800-53B and FIPS 200, along with Control family and Common control. System Compliance (Authorization) adds 23 cards at 14%, drilling decision roles and outcomes through fronts such as AO, AODR, ATO, DATO, and IATT, plus the ISSO, ISSM, and ISSE role cards.
Compliance Maintenance (Monitoring) contributes 20 cards at 13%, covering SP 800-137, ISCM strategy, and Monitor step alongside operational fronts like CCB, Change management, and Decommissioning. Scope of the System rounds out the deck with 17 cards at 10%, where Categorize step, FIPS 199, SP 800-60, and CNSSI 1253 define impact levels and system boundaries.
The CGRC is dense with terminology — the seven RMF steps, the NIST and FIPS publications, the roles (AO, SCA, System Owner), and the authorization paper trail (SSP, SAR, POA&M, ATO).[3] Spaced flashcards are the most efficient way to keep it all straight. Used alongside our practice test and study guide, they turn review time into measurable progress.
CGRC Flashcards by Domain
The cards are organized by the seven official ISC2 domains, which map to the NIST RMF steps. Lead with the heaviest — Implementation of Controls (17%):[1]
| Domain | Exam weight |
|---|---|
| Implementation of Controls | 17% |
| GRC & Compliance Program | 16% |
| Assessment/Audit of Controls | 16% |
| Selection & Approval of Controls | 14% |
| System Compliance (Authorization) | 14% |
| Compliance Maintenance (Monitoring) | 13% |
| Scope of the System | 10% |
How to Get the Most Out of These Flashcards
- Start with the biggest block. GRC & Risk Management Program has 41 cards and feeds every other domain, so lock down Risk, RMF, and the loss math before anything else.
- Type-drill the formulas and references. Force yourself to produce SLE and ALE from their definitions, and do the same for SP 800-53A, since near-miss recall costs you on exam day.
- Use Match for role and outcome cards. The timed game is ideal for separating ISSO, ISSM, and AO, and for keeping the authorization decisions like ATO and DATO from blurring together.
- Move to the practice test once Quiz holds steady. When multiple-choice scores stay level across all seven domains, switch to full-length questions and send the gaps back to the study guide.
- Work two domains per sitting. With 166 cards, pair a heavy domain with a lighter one such as Scope of the System, then re-Flip yesterday’s misses before starting anything new.
CGRC Flashcards FAQ
Hundreds of free CGRC flashcards, organized across all seven ISC2 domains — the GRC program, scope of the system, control selection, implementation, assessment, system compliance, and compliance maintenance — and built around the NIST Risk Management Framework. They're free with no account required.
Yes. Flashcards use active recall — retrieving an answer from memory — which research shows is one of the most effective study methods, especially in short, spaced sessions. They're ideal for the CGRC's heavy terminology: RMF steps, NIST and FIPS documents, roles, and the authorization paper trail (SSP, SAR, POA&M, ATO).
All seven ISC2 domains, mapped to the NIST RMF: GRC and risk management, scope of the system (FIPS 199 categorization), selection and approval of controls, implementation of controls, assessment and audit, system compliance (authorization), and compliance maintenance (continuous monitoring).
Learn the RMF lifecycle first, then drill by domain. Lead with the heaviest — Implementation (17%), the GRC program (16%), and Assessment (16%). Mix the modes: flip to learn, type to test recall, match for speed, and quiz to check yourself before a full practice test.
Yes — 100% free, all four study modes, no paywall.
Yes. The cards follow the current ISC2 exam outline effective June 15, 2024, covering all seven domains, and reflect that CGRC is the renamed CAP (Certified Authorization Professional) built on the NIST RMF.
CGRC flashcard bank
All 166 cards, by topic
A reference copy of every card in this deck. Each answer stays hidden until you choose to show it. To study with Flip, Match, Type and Quiz modes and track what you have mastered, use Study Flashcards at the top of the page.
GRC & Risk Management Program (41)
- RMF
Show answerHide answer
The NIST Risk Management Framework — a 7-step process for managing system security and privacy risk (SP 800-37 Rev. 2).
- GRC
Show answerHide answer
Governance, Risk, and Compliance — directing the organization, managing its risk, and meeting its obligations.
- The 7 RMF steps
Show answerHide answer
Prepare, Categorize, Select, Implement, Assess, Authorize, Monitor (mnemonic: PCSIAAM).
- Governance
Show answerHide answer
Setting direction and accountability through policy, oversight, and defined roles.
- Compliance
Show answerHide answer
Meeting legal, regulatory, and contractual obligations.
- Risk management
Show answerHide answer
Identifying, assessing, and treating risk to the organization's mission.
- Confidentiality
Show answerHide answer
Preserving authorized restrictions on access and disclosure of information.
- Integrity
Show answerHide answer
Guarding against improper modification or destruction; includes authenticity and non-repudiation.
- Availability
Show answerHide answer
Ensuring timely and reliable access to and use of information.
- Non-repudiation
Show answerHide answer
Assurance that a party cannot deny having taken an action; provided by signatures and logging.
- Policy hierarchy
Show answerHide answer
Policy → standard → procedure → guideline (only guidelines are optional).
- Policy
Show answerHide answer
A high-level management statement of intent and direction; mandatory.
- Standard
Show answerHide answer
A mandatory, specific requirement that supports a policy (e.g., 'use AES-256').
- Procedure
Show answerHide answer
Detailed step-by-step instructions for carrying out a task; mandatory.
- Guideline
Show answerHide answer
A recommended, discretionary best practice; not mandatory.
- Qualitative risk analysis
Show answerHide answer
Subjective ranking of risk as high, medium, or low; fast but not dollar-based.
- Quantitative risk analysis
Show answerHide answer
Objective, dollar-based risk analysis using SLE, ARO, and ALE.
- SLE
Show answerHide answer
Single Loss Expectancy = Asset Value × Exposure Factor (loss from one event).
- EF (Exposure Factor)
Show answerHide answer
The percentage of an asset's value lost if a specific risk event occurs.
- ARO
Show answerHide answer
Annualized Rate of Occurrence — the expected number of events per year.
- ALE
Show answerHide answer
Annualized Loss Expectancy = SLE × ARO (the expected yearly cost of a risk).
- Cost-justified control
Show answerHide answer
A control whose annual cost is less than the reduction in ALE it provides.
- Risk
Show answerHide answer
The likelihood a threat exploits a vulnerability, and the resulting impact on an asset.
- Threat
Show answerHide answer
Any potential event or actor that could harm an asset by exploiting a vulnerability.
- Vulnerability
Show answerHide answer
A weakness in a system, process, or control that a threat can exploit.
- Risk appetite
Show answerHide answer
The broad amount and type of risk an organization will accept to pursue value (strategic).
- Risk tolerance
Show answerHide answer
The level of risk variation an organization will accept in practice (operational).
- NIST CSF
Show answerHide answer
The NIST Cybersecurity Framework — a voluntary framework to manage and reduce cyber risk.
- ISO/IEC 27001
Show answerHide answer
The standard for an Information Security Management System (ISMS).
- ISO 31000
Show answerHide answer
The standard for enterprise / organizational risk management.
- COBIT
Show answerHide answer
A framework for IT governance aligned to business objectives.
- FedRAMP
Show answerHide answer
Standardized security authorization for cloud services used by U.S. federal agencies.
- PCI-DSS
Show answerHide answer
The Payment Card Industry Data Security Standard for protecting cardholder data.
- CMMC
Show answerHide answer
Cybersecurity Maturity Model Certification for the U.S. defense industrial base.
- FISMA
Show answerHide answer
The Federal Information Security Modernization Act — drives federal security requirements.
- HIPAA
Show answerHide answer
U.S. law protecting the privacy and security of health information.
- GDPR
Show answerHide answer
The EU General Data Protection Regulation governing personal-data processing.
- SDLC
Show answerHide answer
System Development Life Cycle — requirements, design, development, testing, operations, disposal.
- Information lifecycle
Show answerHide answer
How data is created, used, stored, retained, and disposed of by type.
- CGRC (formerly CAP)
Show answerHide answer
ISC2's Certified in Governance, Risk and Compliance — the renamed Certified Authorization Professional.
- Privacy (CGRC focus)
Show answerHide answer
Protecting personal information; woven throughout every domain of the 2024 outline.
Scope of the System (17)
- Authorization boundary
Show answerHide answer
Everything in a system for authorization: people, processes, hardware, software, data, and connections.
- System scope
Show answerHide answer
The documented name, purpose, functionality, and boundary of the system to be authorized.
- Information type
Show answerHide answer
A category of information (e.g., financial, medical) with its own impact to C, I, and A.
- FIPS 199
Show answerHide answer
The standard for categorizing a system's potential impact (Low/Moderate/High) on C, I, and A.
- Categorize step
Show answerHide answer
RMF step 2: determine the system's impact level using FIPS 199.
- High-water mark
Show answerHide answer
The overall system category equals the HIGHEST impact across C, I, and A — never the average.
- Low impact
Show answerHide answer
A compromise would have a limited adverse effect on operations, assets, or individuals.
- Moderate impact
Show answerHide answer
A compromise would have a serious adverse effect.
- High impact
Show answerHide answer
A compromise would have a severe or catastrophic adverse effect.
- SP 800-60
Show answerHide answer
NIST guide that maps information types to provisional impact levels.
- DPIA
Show answerHide answer
Data Protection Impact Assessment — evaluates privacy risk of processing personal data.
- Security objective
Show answerHide answer
Confidentiality, integrity, or availability — each rated separately during categorization.
- CNSSI 1253
Show answerHide answer
The categorization standard used for National Security Systems.
- Boundary too broad
Show answerHide answer
Inflates cost and complexity and over-scopes the authorization.
- Boundary too narrow
Show answerHide answer
Leaves real risk unaddressed and outside the authorization.
- Impact analysis
Show answerHide answer
Assessing the potential harm to C, I, and A to set the system's category.
- Why scope matters
Show answerHide answer
Categorization drives which baseline, how much assurance, and what the AO accepts risk for.
Selection & Approval of Controls (20)
- Select step
Show answerHide answer
RMF step 3: choose and tailor the control set based on the system's categorization.
- Control selection flow
Show answerHide answer
FIPS 199 → FIPS 200 → pick the 800-53B baseline → tailor it.
- FIPS 200
Show answerHide answer
The standard for the minimum security requirements that correspond to an impact level.
- Control baseline
Show answerHide answer
A predefined Low/Moderate/High starting control set in SP 800-53B — a starting point, not a fixed minimum.
- SP 800-53B
Show answerHide answer
The NIST publication that defines the Low, Moderate, and High control baselines.
- SP 800-53 Rev. 5
Show answerHide answer
The catalog of security and privacy controls, organized into 20 control families.
- Control family
Show answerHide answer
A group of related controls (e.g., AC Access Control, AU Audit, SC System & Communications).
- Tailoring
Show answerHide answer
Adjusting a baseline: scoping, parameterizing, supplementing, overlays, and compensating controls.
- Scoping
Show answerHide answer
Removing controls from a baseline that genuinely do not apply to the system.
- Overlay
Show answerHide answer
A fully specified set of control adjustments tailored to a community, technology, or mission.
- Common control
Show answerHide answer
A control provided once at the organization level and inherited by many systems.
- Compensating control
Show answerHide answer
An alternative safeguard providing equivalent protection when the baseline control isn't feasible.
- Hybrid control
Show answerHide answer
A control implemented partly as a common control and partly as system-specific.
- Control inheritance
Show answerHide answer
When a system receives protection from controls developed and assessed by another entity.
- Privacy control
Show answerHide answer
A safeguard to ensure compliance with privacy requirements and manage privacy risk.
- Low baseline (~150)
Show answerHide answer
The control baseline for a low-impact system (about 150 controls).
- Moderate baseline (~300)
Show answerHide answer
The control baseline for a moderate-impact system (about 300 controls).
- High baseline (~390)
Show answerHide answer
The control baseline for a high-impact system (about 390 controls).
- 20 control families
Show answerHide answer
SP 800-53 Rev. 5 organizes its controls into 20 families (AC, AU, SC, IA, and so on).
- Baseline is a starting point
Show answerHide answer
The baseline is tailored, not adopted unchanged — it is not a mandatory minimum set.
Implementation of Controls (20)
- Implement step
Show answerHide answer
RMF step 4: deploy the selected controls and document HOW each is implemented.
- SSP
Show answerHide answer
System Security Plan — the master document describing the system and how every control is implemented.
- SSP owner
Show answerHide answer
The System Owner develops and maintains the System Security Plan.
- Implementation strategy
Show answerHide answer
The plan for resourcing, funding, timeline, and measuring control effectiveness.
- Management control
Show answerHide answer
A control implemented through policy, planning, and risk management (e.g., a risk assessment).
- Operational control
Show answerHide answer
A control executed by people and procedures (e.g., training, incident response).
- Technical control
Show answerHide answer
A control enforced by technology (e.g., encryption, access control, audit logging).
- Preventive control
Show answerHide answer
A control that stops an incident before it happens (e.g., access control, encryption).
- Detective control
Show answerHide answer
A control that identifies an incident in progress or after it occurs (e.g., logging, IDS).
- Corrective control
Show answerHide answer
A control that restores a system after an incident (e.g., backups, patching).
- Deterrent control
Show answerHide answer
A control that discourages a threat actor (e.g., warning banners, visible cameras).
- Documenting implementation
Show answerHide answer
Recording purpose, scope, and how each control is implemented in policies, procedures, and the SSP.
- Alternate control
Show answerHide answer
A substitute deployed when the prescribed control cannot be implemented as written.
- Implementation & compliance
Show answerHide answer
Controls must be implemented consistent with the organization's compliance obligations.
- Review/training frequency
Show answerHide answer
How often implemented controls, documentation, and training are reviewed and refreshed.
- SP 800-18
Show answerHide answer
NIST guide for developing System Security Plans (the SSP).
- Heaviest domain
Show answerHide answer
Implementation of Controls is the largest CGRC domain at 17% of the exam.
- Encryption (technical control)
Show answerHide answer
A technical control protecting confidentiality of data at rest and in transit.
- Security awareness training
Show answerHide answer
An operational control reducing human-error risk across the organization.
- Common control reuse
Show answerHide answer
Inherited common controls are not reimplemented per system — they're inherited once.
Assessment/Audit of Controls (25)
- Assess step
Show answerHide answer
RMF step 5: determine whether controls are implemented correctly and working as intended.
- SCA
Show answerHide answer
Security Control Assessor — independently assesses and tests controls and writes the SAR.
- SCA independence
Show answerHide answer
The assessor must be independent of the System Owner to keep the assessment objective.
- SAP
Show answerHide answer
Security Assessment Plan — defines the scope, roles, evidence, and procedures for the assessment.
- Assessment methods
Show answerHide answer
Examine, Interview, Test (EIT) — defined in SP 800-53A.
- Examine
Show answerHide answer
Reviewing documents, policies, and configurations to assess a control.
- Interview
Show answerHide answer
Questioning the people who operate a control to assess it.
- Test
Show answerHide answer
Exercising a control to see how it behaves (e.g., a vulnerability scan or penetration test).
- SP 800-53A
Show answerHide answer
NIST guide for assessing security and privacy controls (the assessment procedures).
- SAR
Show answerHide answer
Security Assessment Report — the assessor's findings and recommendations.
- Satisfied (SAR)
Show answerHide answer
A SAR status meaning the control is implemented correctly and works as intended.
- Other-than-satisfied
Show answerHide answer
A SAR status meaning the control has a weakness or gap; it flows into the POA&M.
- Not applicable (SAR)
Show answerHide answer
A SAR status meaning the control does not apply to the system; document the justification.
- POA&M
Show answerHide answer
Plan of Action and Milestones — tracks unresolved weaknesses, owner, resources, and target dates.
- POA&M owner
Show answerHide answer
The System Owner owns and maintains the POA&M.
- Risk response
Show answerHide answer
How a risk is treated: avoid, accept, mitigate (reduce), or transfer/share.
- Risk avoidance
Show answerHide answer
Eliminating a risk by ceasing the activity that creates it.
- Risk mitigation
Show answerHide answer
Reducing risk to an acceptable level by implementing controls.
- Risk transfer/share
Show answerHide answer
Shifting the financial impact of a risk to a third party (e.g., insurance).
- Risk acceptance
Show answerHide answer
A documented, management-approved decision to tolerate a risk and its residual impact.
- Residual risk
Show answerHide answer
The risk that remains after controls are applied; the AO formally accepts it.
- Transfer ≠ accountability
Show answerHide answer
Transferring a risk's financial impact never transfers your accountability or liability.
- Penetration test
Show answerHide answer
An authorized, simulated attack that exploits weaknesses to show real impact.
- Vulnerability scan
Show answerHide answer
An automated check that finds known weaknesses without exploiting them.
- Final assessment report
Show answerHide answer
Documents final compliance per control: compliant, non-compliant, or not applicable.
System Compliance (Authorization) (23)
- Authorize step
Show answerHide answer
RMF step 6: a senior official makes a risk-based decision to authorize the system.
- Authorization package
Show answerHide answer
The SSP, SAR, and POA&M submitted to the Authorizing Official for the decision.
- AO
Show answerHide answer
Authorizing Official — the senior official who accepts residual risk and signs the ATO.
- Only the AO authorizes
Show answerHide answer
The Authorizing Official is the only role that can authorize a system to operate.
- AODR
Show answerHide answer
AO Designated Representative — coordinates the process but cannot make or sign the decision.
- System Owner
Show answerHide answer
Responsible for the system; develops the SSP, owns the POA&M, submits the authorization package.
- ISSO
Show answerHide answer
Information System Security Officer — handles the day-to-day operational security of a system.
- ISSM
Show answerHide answer
Information System Security Manager — manages ISSOs, aggregates risk, advises the AO.
- ISSE
Show answerHide answer
Information System Security Engineer — builds security into the system's design.
- Common Control Provider
Show answerHide answer
Supplies the inherited common controls used across many systems.
- Information Owner
Show answerHide answer
Sets requirements for how its information is handled; involved in categorization.
- Risk Executive
Show answerHide answer
Provides an organization-wide risk perspective to keep system decisions consistent.
- SCA assesses, AO accepts
Show answerHide answer
The separation rule: the assessor evaluates controls; the AO accepts the risk.
- ATO
Show answerHide answer
Authorization to Operate — the AO's formal decision to operate and accept residual risk.
- ATO with conditions
Show answerHide answer
Authorization to operate provided specific weaknesses are remediated on a schedule.
- DATO
Show answerHide answer
Denial of Authorization to Operate — the risk is unacceptable; the system may not operate.
- IATT
Show answerHide answer
Interim Authority to Test — permits testing in an operational setting, NOT production operation.
- IATT ≠ ATO
Show answerHide answer
An IATT authorizes testing only; only an ATO authorizes production operation.
- Risk-based decision
Show answerHide answer
Authorization is a judgment about residual risk, never a purely technical pass/fail.
- Risk acceptance criteria
Show answerHide answer
The thresholds the AO uses to decide whether residual risk is acceptable.
- Stakeholder concurrence
Show answerHide answer
Agreement from relevant parties on the risk treatment before the compliance decision.
- Reciprocity
Show answerHide answer
Mutual agreement to accept another organization's assessments and security posture.
- 3PAO
Show answerHide answer
Third-Party Assessment Organization — independent assessor used in programs like FedRAMP.
Compliance Maintenance (Monitoring) (20)
- Monitor step
Show answerHide answer
RMF step 7: continuously monitor control effectiveness and risk after authorization.
- Continuous monitoring (ISCM)
Show answerHide answer
Ongoing awareness of security, vulnerabilities, and threats to keep risk decisions current.
- SP 800-137
Show answerHide answer
NIST guide for Information Security Continuous Monitoring (ISCM).
- Ongoing authorization
Show answerHide answer
Keeping authorization current through continuous monitoring, not periodic reauthorization.
- ISCM strategy
Show answerHide answer
Defines what to monitor, how often, and the metrics that trigger action.
- Change management
Show answerHide answer
The controlled process to evaluate, approve, implement, and track system changes.
- Security impact analysis
Show answerHide answer
Evaluating how a proposed change affects the security state before approval.
- CCB
Show answerHide answer
Change Control Board — approves, defers, or rejects proposed changes to a system.
- Rollback plan
Show answerHide answer
A documented way to reverse a change if it fails or harms security.
- Significant change
Show answerHide answer
A change large enough to trigger reassessment and possibly reauthorization.
- Decommissioning
Show answerHide answer
Securely retiring a system at end of life, including media sanitization and documentation.
- Media sanitization
Show answerHide answer
Removing data from media (clear, purge, or destroy) so it cannot be recovered.
- Ongoing assessment
Show answerHide answer
Re-checking control effectiveness over time as part of continuous monitoring.
- Monitor ≠ done
Show answerHide answer
Authorization is a lifecycle; continuous monitoring feeds ongoing authorization decisions.
- Configuration management
Show answerHide answer
Controlling and documenting the configuration of an authorized system (SP 800-128).
- Incident response (Monitor)
Show answerHide answer
Detecting, responding to, and learning from incidents during operations.
- Contingency planning
Show answerHide answer
Plans to keep or restore operations after a disruption (continuity and recovery).
- Evidence collection
Show answerHide answer
Gathering ongoing documentation and test results to demonstrate continued compliance.
- Revise monitoring strategy
Show answerHide answer
Updating the ISCM strategy as laws, regulations, or suppliers change.
- Baseline configuration
Show answerHide answer
An approved, documented set of system settings used as a reference for changes.
References
- 1.ISC2. “CGRC Certification Exam Outline (effective June 15, 2024).” isc2.org. ↑
- 2.ISC2. “CGRC — Certified in Governance, Risk and Compliance.” isc2.org. ↑
- 3.National Institute of Standards and Technology. “SP 800-37 Rev. 2: Risk Management Framework for Information Systems and Organizations.” csrc.nist.gov. ↑

Career Employer
Career Employer is the ultimate resource to help you get started working the job of your dreams. We cover topics from general career information, career searching, exam preparation with free study materials, career interviewing, and becoming successful in your career of choice.
All PostsCareer Employer’s Editorial Process
Here at Career Employer, we focus a lot on providing factually accurate information that is always up to date. We strive to provide correct information using strict editorial processes, article editing, and fact-checking for all of the information found on our website. We only utilize trustworthy and relevant resources. To find out more, make sure to read our full editorial process page here.
