Lesson 11: Governance, Risk, and Compliance
Week of Tue, Nov 24 · lesson closes Mon, Nov 30
Take Meerk's quiz for Lesson 11
This lesson's items
Exact due times are in Canvas.
Watch — Professor Messer
Watch — Professor Messer: Governance and Compliance (SY0-701)
Free, independent educational resource. Not affiliated with or endorsed by CompTIA. Watch, then read the notes below.
Know these cold
- Risk management: risk = likelihood × impact. Responses: mitigate (reduce), accept (tolerate), transfer (insurance), avoid (stop the activity).
- Compliance frameworks: NIST CSF (5 functions: Identify, Protect, Detect, Respond, Recover), ISO 27001 (ISMS), SOC 2 (trust service criteria for service providers), PCI-DSS (payment card data), HIPAA (health information).
- Data classification: public, internal, confidential, top secret (government). DLP (Data Loss Prevention) enforces classification policies to prevent exfiltration.
Meerk's quiz — open the Lesson 11 gate
10 questions, no time limit. 85% on your first attempt in a 24-hour window opens the gate. Retakes inside the window are practice — they help you learn, they don't count. Work alone; the point is to know it, not to have seen it.
Dinner Table Question
Ask at home: If a company follows all compliance requirements, does that mean they are secure?
En español: Si una empresa sigue todos los requisitos de cumplimiento, ¿eso significa que está segura?