Career Employer

Your FREE CGRC Flashcards 2026 – 150+ Cards

Realistic, CGRC exam-style flashcards across all 7 ISC2 domains and the NIST RMF — flip, match, type, and quiz yourself.

How well do you know them?

To find us again, just search “Career Employer CGRC”

By

Click Study Flashcards above to open the flashcard hub — hundreds of CGRC cards you can flip, match, type, or quiz yourself on. Every card is drawn from the seven official ISC2 domains and the NIST Risk Management Framework, so you study exactly what the exam tests.[1] Pair them with our free practice test and study guide.

CGRC is one of the 9 ISC2 certifications — explore our ISC2 flashcards to compare and prep across the whole family.

CGRC Flashcard Study Modes

Flip mode lets you read a term, think, and turn the card over at your own pace. Type mode shows the definition and asks you to produce the term exactly, so a front like POA&M has to come from memory. Match is a timed term-to-definition game for speed, and Quiz turns the same cards into multiple-choice questions.

Free CGRC flashcards from Career Employer — active recall for the ISC2 Certified in Governance, Risk and Compliance exam

Why Flashcards Work for the CGRC

Implementation of Controls carries the heaviest official weight at 17% and holds 20 cards. These drill how controls move from paper into practice, with the SSP, SSP owner, and SP 800-18 cards covering documentation, while Implement step, Technical control, and Deterrent control fix the vocabulary of control types and phases. There is even a card front called Heaviest domain to remind you where the exam leans.

GRC & Risk Management Program is the largest block in the deck with 41 cards. It mixes program vocabulary such as GRC, Risk, and RMF with the quantitative risk terms you have to keep straight under pressure, including SLE, ARO, and ALE. Regulatory and framework fronts like GDPR and CMMC also live here, so expect broad coverage rather than one narrow topic.

Assessment/Audit of Controls holds 25 cards at 16%. The assessment method fronts Examine, Interview, and Test are the backbone, supported by SP 800-53A, and the artifact terms SCA, SAP, SAR, and POA&M that tell you who assesses, what plan is used, what report comes out, and what happens to findings.

Selection & Approval of Controls has 20 cards at 14%, built around Scoping, Tailoring, and Overlay plus the baseline references SP 800-53B and FIPS 200, along with Control family and Common control. System Compliance (Authorization) adds 23 cards at 14%, drilling decision roles and outcomes through fronts such as AO, AODR, ATO, DATO, and IATT, plus the ISSO, ISSM, and ISSE role cards.

Compliance Maintenance (Monitoring) contributes 20 cards at 13%, covering SP 800-137, ISCM strategy, and Monitor step alongside operational fronts like CCB, Change management, and Decommissioning. Scope of the System rounds out the deck with 17 cards at 10%, where Categorize step, FIPS 199, SP 800-60, and CNSSI 1253 define impact levels and system boundaries.

The CGRC is dense with terminology — the seven RMF steps, the NIST and FIPS publications, the roles (AO, SCA, System Owner), and the authorization paper trail (SSP, SAR, POA&M, ATO).[3] Spaced flashcards are the most efficient way to keep it all straight. Used alongside our practice test and study guide, they turn review time into measurable progress.

CGRC Flashcards by Domain

The cards are organized by the seven official ISC2 domains, which map to the NIST RMF steps. Lead with the heaviest — Implementation of Controls (17%):[1]

CGRC flashcards by domain and weight
DomainExam weight
Implementation of Controls17%
GRC & Compliance Program16%
Assessment/Audit of Controls16%
Selection & Approval of Controls14%
System Compliance (Authorization)14%
Compliance Maintenance (Monitoring)13%
Scope of the System10%

How to Get the Most Out of These Flashcards

  • Start with the biggest block. GRC & Risk Management Program has 41 cards and feeds every other domain, so lock down Risk, RMF, and the loss math before anything else.
  • Type-drill the formulas and references. Force yourself to produce SLE and ALE from their definitions, and do the same for SP 800-53A, since near-miss recall costs you on exam day.
  • Use Match for role and outcome cards. The timed game is ideal for separating ISSO, ISSM, and AO, and for keeping the authorization decisions like ATO and DATO from blurring together.
  • Move to the practice test once Quiz holds steady. When multiple-choice scores stay level across all seven domains, switch to full-length questions and send the gaps back to the study guide.
  • Work two domains per sitting. With 166 cards, pair a heavy domain with a lighter one such as Scope of the System, then re-Flip yesterday’s misses before starting anything new.

CGRC Flashcards FAQ

Hundreds of free CGRC flashcards, organized across all seven ISC2 domains — the GRC program, scope of the system, control selection, implementation, assessment, system compliance, and compliance maintenance — and built around the NIST Risk Management Framework. They're free with no account required.

CGRC flashcard bank

All 166 cards, by topic

A reference copy of every card in this deck. Each answer stays hidden until you choose to show it. To study with Flip, Match, Type and Quiz modes and track what you have mastered, use Study Flashcards at the top of the page.

GRC & Risk Management Program (41)

RMF
Show answer

The NIST Risk Management Framework — a 7-step process for managing system security and privacy risk (SP 800-37 Rev. 2).

GRC
Show answer

Governance, Risk, and Compliance — directing the organization, managing its risk, and meeting its obligations.

The 7 RMF steps
Show answer

Prepare, Categorize, Select, Implement, Assess, Authorize, Monitor (mnemonic: PCSIAAM).

Governance
Show answer

Setting direction and accountability through policy, oversight, and defined roles.

Compliance
Show answer

Meeting legal, regulatory, and contractual obligations.

Risk management
Show answer

Identifying, assessing, and treating risk to the organization's mission.

Confidentiality
Show answer

Preserving authorized restrictions on access and disclosure of information.

Integrity
Show answer

Guarding against improper modification or destruction; includes authenticity and non-repudiation.

Availability
Show answer

Ensuring timely and reliable access to and use of information.

Non-repudiation
Show answer

Assurance that a party cannot deny having taken an action; provided by signatures and logging.

Policy hierarchy
Show answer

Policy → standard → procedure → guideline (only guidelines are optional).

Policy
Show answer

A high-level management statement of intent and direction; mandatory.

Standard
Show answer

A mandatory, specific requirement that supports a policy (e.g., 'use AES-256').

Procedure
Show answer

Detailed step-by-step instructions for carrying out a task; mandatory.

Guideline
Show answer

A recommended, discretionary best practice; not mandatory.

Qualitative risk analysis
Show answer

Subjective ranking of risk as high, medium, or low; fast but not dollar-based.

Quantitative risk analysis
Show answer

Objective, dollar-based risk analysis using SLE, ARO, and ALE.

SLE
Show answer

Single Loss Expectancy = Asset Value × Exposure Factor (loss from one event).

EF (Exposure Factor)
Show answer

The percentage of an asset's value lost if a specific risk event occurs.

ARO
Show answer

Annualized Rate of Occurrence — the expected number of events per year.

ALE
Show answer

Annualized Loss Expectancy = SLE × ARO (the expected yearly cost of a risk).

Cost-justified control
Show answer

A control whose annual cost is less than the reduction in ALE it provides.

Risk
Show answer

The likelihood a threat exploits a vulnerability, and the resulting impact on an asset.

Threat
Show answer

Any potential event or actor that could harm an asset by exploiting a vulnerability.

Vulnerability
Show answer

A weakness in a system, process, or control that a threat can exploit.

Risk appetite
Show answer

The broad amount and type of risk an organization will accept to pursue value (strategic).

Risk tolerance
Show answer

The level of risk variation an organization will accept in practice (operational).

NIST CSF
Show answer

The NIST Cybersecurity Framework — a voluntary framework to manage and reduce cyber risk.

ISO/IEC 27001
Show answer

The standard for an Information Security Management System (ISMS).

ISO 31000
Show answer

The standard for enterprise / organizational risk management.

COBIT
Show answer

A framework for IT governance aligned to business objectives.

FedRAMP
Show answer

Standardized security authorization for cloud services used by U.S. federal agencies.

PCI-DSS
Show answer

The Payment Card Industry Data Security Standard for protecting cardholder data.

CMMC
Show answer

Cybersecurity Maturity Model Certification for the U.S. defense industrial base.

FISMA
Show answer

The Federal Information Security Modernization Act — drives federal security requirements.

HIPAA
Show answer

U.S. law protecting the privacy and security of health information.

GDPR
Show answer

The EU General Data Protection Regulation governing personal-data processing.

SDLC
Show answer

System Development Life Cycle — requirements, design, development, testing, operations, disposal.

Information lifecycle
Show answer

How data is created, used, stored, retained, and disposed of by type.

CGRC (formerly CAP)
Show answer

ISC2's Certified in Governance, Risk and Compliance — the renamed Certified Authorization Professional.

Privacy (CGRC focus)
Show answer

Protecting personal information; woven throughout every domain of the 2024 outline.

Scope of the System (17)

Authorization boundary
Show answer

Everything in a system for authorization: people, processes, hardware, software, data, and connections.

System scope
Show answer

The documented name, purpose, functionality, and boundary of the system to be authorized.

Information type
Show answer

A category of information (e.g., financial, medical) with its own impact to C, I, and A.

FIPS 199
Show answer

The standard for categorizing a system's potential impact (Low/Moderate/High) on C, I, and A.

Categorize step
Show answer

RMF step 2: determine the system's impact level using FIPS 199.

High-water mark
Show answer

The overall system category equals the HIGHEST impact across C, I, and A — never the average.

Low impact
Show answer

A compromise would have a limited adverse effect on operations, assets, or individuals.

Moderate impact
Show answer

A compromise would have a serious adverse effect.

High impact
Show answer

A compromise would have a severe or catastrophic adverse effect.

SP 800-60
Show answer

NIST guide that maps information types to provisional impact levels.

DPIA
Show answer

Data Protection Impact Assessment — evaluates privacy risk of processing personal data.

Security objective
Show answer

Confidentiality, integrity, or availability — each rated separately during categorization.

CNSSI 1253
Show answer

The categorization standard used for National Security Systems.

Boundary too broad
Show answer

Inflates cost and complexity and over-scopes the authorization.

Boundary too narrow
Show answer

Leaves real risk unaddressed and outside the authorization.

Impact analysis
Show answer

Assessing the potential harm to C, I, and A to set the system's category.

Why scope matters
Show answer

Categorization drives which baseline, how much assurance, and what the AO accepts risk for.

Selection & Approval of Controls (20)

Select step
Show answer

RMF step 3: choose and tailor the control set based on the system's categorization.

Control selection flow
Show answer

FIPS 199 → FIPS 200 → pick the 800-53B baseline → tailor it.

FIPS 200
Show answer

The standard for the minimum security requirements that correspond to an impact level.

Control baseline
Show answer

A predefined Low/Moderate/High starting control set in SP 800-53B — a starting point, not a fixed minimum.

SP 800-53B
Show answer

The NIST publication that defines the Low, Moderate, and High control baselines.

SP 800-53 Rev. 5
Show answer

The catalog of security and privacy controls, organized into 20 control families.

Control family
Show answer

A group of related controls (e.g., AC Access Control, AU Audit, SC System & Communications).

Tailoring
Show answer

Adjusting a baseline: scoping, parameterizing, supplementing, overlays, and compensating controls.

Scoping
Show answer

Removing controls from a baseline that genuinely do not apply to the system.

Overlay
Show answer

A fully specified set of control adjustments tailored to a community, technology, or mission.

Common control
Show answer

A control provided once at the organization level and inherited by many systems.

Compensating control
Show answer

An alternative safeguard providing equivalent protection when the baseline control isn't feasible.

Hybrid control
Show answer

A control implemented partly as a common control and partly as system-specific.

Control inheritance
Show answer

When a system receives protection from controls developed and assessed by another entity.

Privacy control
Show answer

A safeguard to ensure compliance with privacy requirements and manage privacy risk.

Low baseline (~150)
Show answer

The control baseline for a low-impact system (about 150 controls).

Moderate baseline (~300)
Show answer

The control baseline for a moderate-impact system (about 300 controls).

High baseline (~390)
Show answer

The control baseline for a high-impact system (about 390 controls).

20 control families
Show answer

SP 800-53 Rev. 5 organizes its controls into 20 families (AC, AU, SC, IA, and so on).

Baseline is a starting point
Show answer

The baseline is tailored, not adopted unchanged — it is not a mandatory minimum set.

Implementation of Controls (20)

Implement step
Show answer

RMF step 4: deploy the selected controls and document HOW each is implemented.

SSP
Show answer

System Security Plan — the master document describing the system and how every control is implemented.

SSP owner
Show answer

The System Owner develops and maintains the System Security Plan.

Implementation strategy
Show answer

The plan for resourcing, funding, timeline, and measuring control effectiveness.

Management control
Show answer

A control implemented through policy, planning, and risk management (e.g., a risk assessment).

Operational control
Show answer

A control executed by people and procedures (e.g., training, incident response).

Technical control
Show answer

A control enforced by technology (e.g., encryption, access control, audit logging).

Preventive control
Show answer

A control that stops an incident before it happens (e.g., access control, encryption).

Detective control
Show answer

A control that identifies an incident in progress or after it occurs (e.g., logging, IDS).

Corrective control
Show answer

A control that restores a system after an incident (e.g., backups, patching).

Deterrent control
Show answer

A control that discourages a threat actor (e.g., warning banners, visible cameras).

Documenting implementation
Show answer

Recording purpose, scope, and how each control is implemented in policies, procedures, and the SSP.

Alternate control
Show answer

A substitute deployed when the prescribed control cannot be implemented as written.

Implementation & compliance
Show answer

Controls must be implemented consistent with the organization's compliance obligations.

Review/training frequency
Show answer

How often implemented controls, documentation, and training are reviewed and refreshed.

SP 800-18
Show answer

NIST guide for developing System Security Plans (the SSP).

Heaviest domain
Show answer

Implementation of Controls is the largest CGRC domain at 17% of the exam.

Encryption (technical control)
Show answer

A technical control protecting confidentiality of data at rest and in transit.

Security awareness training
Show answer

An operational control reducing human-error risk across the organization.

Common control reuse
Show answer

Inherited common controls are not reimplemented per system — they're inherited once.

Assessment/Audit of Controls (25)

Assess step
Show answer

RMF step 5: determine whether controls are implemented correctly and working as intended.

SCA
Show answer

Security Control Assessor — independently assesses and tests controls and writes the SAR.

SCA independence
Show answer

The assessor must be independent of the System Owner to keep the assessment objective.

SAP
Show answer

Security Assessment Plan — defines the scope, roles, evidence, and procedures for the assessment.

Assessment methods
Show answer

Examine, Interview, Test (EIT) — defined in SP 800-53A.

Examine
Show answer

Reviewing documents, policies, and configurations to assess a control.

Interview
Show answer

Questioning the people who operate a control to assess it.

Test
Show answer

Exercising a control to see how it behaves (e.g., a vulnerability scan or penetration test).

SP 800-53A
Show answer

NIST guide for assessing security and privacy controls (the assessment procedures).

SAR
Show answer

Security Assessment Report — the assessor's findings and recommendations.

Satisfied (SAR)
Show answer

A SAR status meaning the control is implemented correctly and works as intended.

Other-than-satisfied
Show answer

A SAR status meaning the control has a weakness or gap; it flows into the POA&M.

Not applicable (SAR)
Show answer

A SAR status meaning the control does not apply to the system; document the justification.

POA&M
Show answer

Plan of Action and Milestones — tracks unresolved weaknesses, owner, resources, and target dates.

POA&M owner
Show answer

The System Owner owns and maintains the POA&M.

Risk response
Show answer

How a risk is treated: avoid, accept, mitigate (reduce), or transfer/share.

Risk avoidance
Show answer

Eliminating a risk by ceasing the activity that creates it.

Risk mitigation
Show answer

Reducing risk to an acceptable level by implementing controls.

Risk transfer/share
Show answer

Shifting the financial impact of a risk to a third party (e.g., insurance).

Risk acceptance
Show answer

A documented, management-approved decision to tolerate a risk and its residual impact.

Residual risk
Show answer

The risk that remains after controls are applied; the AO formally accepts it.

Transfer ≠ accountability
Show answer

Transferring a risk's financial impact never transfers your accountability or liability.

Penetration test
Show answer

An authorized, simulated attack that exploits weaknesses to show real impact.

Vulnerability scan
Show answer

An automated check that finds known weaknesses without exploiting them.

Final assessment report
Show answer

Documents final compliance per control: compliant, non-compliant, or not applicable.

System Compliance (Authorization) (23)

Authorize step
Show answer

RMF step 6: a senior official makes a risk-based decision to authorize the system.

Authorization package
Show answer

The SSP, SAR, and POA&M submitted to the Authorizing Official for the decision.

AO
Show answer

Authorizing Official — the senior official who accepts residual risk and signs the ATO.

Only the AO authorizes
Show answer

The Authorizing Official is the only role that can authorize a system to operate.

AODR
Show answer

AO Designated Representative — coordinates the process but cannot make or sign the decision.

System Owner
Show answer

Responsible for the system; develops the SSP, owns the POA&M, submits the authorization package.

ISSO
Show answer

Information System Security Officer — handles the day-to-day operational security of a system.

ISSM
Show answer

Information System Security Manager — manages ISSOs, aggregates risk, advises the AO.

ISSE
Show answer

Information System Security Engineer — builds security into the system's design.

Common Control Provider
Show answer

Supplies the inherited common controls used across many systems.

Information Owner
Show answer

Sets requirements for how its information is handled; involved in categorization.

Risk Executive
Show answer

Provides an organization-wide risk perspective to keep system decisions consistent.

SCA assesses, AO accepts
Show answer

The separation rule: the assessor evaluates controls; the AO accepts the risk.

ATO
Show answer

Authorization to Operate — the AO's formal decision to operate and accept residual risk.

ATO with conditions
Show answer

Authorization to operate provided specific weaknesses are remediated on a schedule.

DATO
Show answer

Denial of Authorization to Operate — the risk is unacceptable; the system may not operate.

IATT
Show answer

Interim Authority to Test — permits testing in an operational setting, NOT production operation.

IATT ≠ ATO
Show answer

An IATT authorizes testing only; only an ATO authorizes production operation.

Risk-based decision
Show answer

Authorization is a judgment about residual risk, never a purely technical pass/fail.

Risk acceptance criteria
Show answer

The thresholds the AO uses to decide whether residual risk is acceptable.

Stakeholder concurrence
Show answer

Agreement from relevant parties on the risk treatment before the compliance decision.

Reciprocity
Show answer

Mutual agreement to accept another organization's assessments and security posture.

3PAO
Show answer

Third-Party Assessment Organization — independent assessor used in programs like FedRAMP.

Compliance Maintenance (Monitoring) (20)

Monitor step
Show answer

RMF step 7: continuously monitor control effectiveness and risk after authorization.

Continuous monitoring (ISCM)
Show answer

Ongoing awareness of security, vulnerabilities, and threats to keep risk decisions current.

SP 800-137
Show answer

NIST guide for Information Security Continuous Monitoring (ISCM).

Ongoing authorization
Show answer

Keeping authorization current through continuous monitoring, not periodic reauthorization.

ISCM strategy
Show answer

Defines what to monitor, how often, and the metrics that trigger action.

Change management
Show answer

The controlled process to evaluate, approve, implement, and track system changes.

Security impact analysis
Show answer

Evaluating how a proposed change affects the security state before approval.

CCB
Show answer

Change Control Board — approves, defers, or rejects proposed changes to a system.

Rollback plan
Show answer

A documented way to reverse a change if it fails or harms security.

Significant change
Show answer

A change large enough to trigger reassessment and possibly reauthorization.

Decommissioning
Show answer

Securely retiring a system at end of life, including media sanitization and documentation.

Media sanitization
Show answer

Removing data from media (clear, purge, or destroy) so it cannot be recovered.

Ongoing assessment
Show answer

Re-checking control effectiveness over time as part of continuous monitoring.

Monitor ≠ done
Show answer

Authorization is a lifecycle; continuous monitoring feeds ongoing authorization decisions.

Configuration management
Show answer

Controlling and documenting the configuration of an authorized system (SP 800-128).

Incident response (Monitor)
Show answer

Detecting, responding to, and learning from incidents during operations.

Contingency planning
Show answer

Plans to keep or restore operations after a disruption (continuity and recovery).

Evidence collection
Show answer

Gathering ongoing documentation and test results to demonstrate continued compliance.

Revise monitoring strategy
Show answer

Updating the ISCM strategy as laws, regulations, or suppliers change.

Baseline configuration
Show answer

An approved, documented set of system settings used as a reference for changes.

References

  1. 1.ISC2. “CGRC Certification Exam Outline (effective June 15, 2024).” isc2.org. ↑
  2. 2.ISC2. “CGRC — Certified in Governance, Risk and Compliance.” isc2.org. ↑
  3. 3.National Institute of Standards and Technology. “SP 800-37 Rev. 2: Risk Management Framework for Information Systems and Organizations.” csrc.nist.gov. ↑
Career Employer

Career Employer is the ultimate resource to help you get started working the job of your dreams. We cover topics from general career information, career searching, exam preparation with free study materials, career interviewing, and becoming successful in your career of choice.

Follow Us:

All Posts

Career Employer’s Editorial Process

Here at Career Employer, we focus a lot on providing factually accurate information that is always up to date. We strive to provide correct information using strict editorial processes, article editing, and fact-checking for all of the information found on our website. We only utilize trustworthy and relevant resources. To find out more, make sure to read our full editorial process page here.