Extended Capabilities
About 5% of the CIS-RC exam — see all 7 domains.
Beyond the core three: Vendor Risk Management (VRM) (third-party/supplier risk and assessments), Business Continuity Management (BCM), Operational Resilience, Privacy Management, integrations (CMDB, Security Operations / SecOps, identity, external GRC data, content packs/UCF), and Performance Analytics (PA) dashboards and content packs for GRC reporting and trend analysis. Continuous monitoring and metrics extend automation.
Sample questions from this domain
Three of the 15 in this domain, with the reasoning. The full set is in the question bank.
Which application extends GRC to manage risk associated with third parties such as suppliers?
- A. Vendor Risk Management ✓
- B. Incident Management
- C. Service Catalog
- D. Knowledge Management
Why: Vendor Risk Management extends GRC to assess and manage third-party/supplier risk. Knowledge Management, Service Catalog, and Incident Management are unrelated to third-party risk.
What is a primary function of integrating GRC with external data sources or security tools?
- A. To delete the risk register
- B. To automate indicators and evidence collection so control/risk monitoring reflects real operational data ✓
- C. To replace the GRC framework entirely
- D. To disable attestations
Why: Integrations feed automated indicators and evidence so monitoring reflects real operational data. They do not replace the framework, delete the register, or disable attestations.
Which capabilities are commonly considered extended/adjacent to core GRC? (Choose two)
- A. Customer chat surveys
- B. Hardware Asset reclamation
- C. Telephony routing
- D. Vendor Risk Management ✓
- E. Business Continuity Management ✓
Why: Vendor Risk Management and Business Continuity Management are extended GRC/IRM capabilities. Hardware asset reclamation, telephony routing, and customer chat surveys belong to other product areas.