23–25 correct
Excellent mastery
You can connect I14 governance, risk, controls, suppliers, metrics, and leadership decisions with strong evidence discipline.
Test your mastery of fictional governance, risk assessment, business impact, treatment, controls, standards, exceptions, third-party risk, metrics, reporting, ownership, validation, and review.
Readiness Check
0/5 ready
Assessment Rules
Answer all 25 questions in the single quiz below.
Choose one answer before revealing the explanation.
Use only the fictional evidence and concepts from Module I14.
Do not assume missing evidence proves compromise, intent, outage, or impact.
Record your total score after completing every question.
Use the mastery review to revisit the lesson connected to each missed concept.
Check Your Understanding
Choose your answers first. Explanations appear only after submission.
Score Guide
23–25 correct
Excellent mastery
You can connect I14 governance, risk, controls, suppliers, metrics, and leadership decisions with strong evidence discipline.
20–22 correct
Strong mastery
Review the few areas where ownership, evidence limits, or treatment choices were unclear.
17–19 correct
Developing mastery
Revisit the matching lessons and strengthen risk scenarios, supplier lifecycle, exceptions, and metric definitions.
13–16 correct
Partial mastery
Complete a structured review of I14.1 through I14.8 before moving forward.
0–12 correct
Rebuild foundations
Return to the lesson workflows, scenario labs, checklists, and portfolio artifacts in order.
Mastery Review
Mastery check
Distinguish authority, accountability, policy ownership, control ownership, risk ownership, escalation, and review.
Review guidance
Revisit I14.1 when decision rights or governance roles are unclear.
Mastery check
Write a complete risk scenario and separate risk level from evidence confidence.
Review guidance
Revisit I14.2 when a score appears without evidence, assumptions, alternatives, and limits.
Mastery check
Connect criticality, dependencies, RTO, RPO, minimum service, and recovery ownership.
Review guidance
Revisit I14.3 when recovery priorities rely only on technical preference.
Mastery check
Compare treatment options and validate business fit, dependencies, rollback, effectiveness, and residual risk.
Review guidance
Revisit I14.4 when implementation is treated as proof of effectiveness.
Mastery check
Distinguish document layers and build controlled, time-bound exceptions.
Review guidance
Revisit I14.5 when deviations lack scope, authority, monitoring, expiration, or sunset plans.
Mastery check
Map suppliers, fourth parties, data, access, contracts, concentration, monitoring, recovery, and exit.
Review guidance
Revisit I14.6 when one report or contract is treated as complete assurance.
Mastery check
Define purpose, scope, numerator, denominator, exclusions, source health, confidence, and decision use.
Review guidance
Revisit I14.7 when percentages or dashboard colors are treated as conclusions.
Mastery check
Prioritize active exposure, missing authority, recovery uncertainty, supplier dependencies, evidence limits, validation, and closure.
Review guidance
Revisit I14.8 when the final package lacks sequencing, ownership, or reassessment.
Defender Habits
Portfolio Prompt
Review your fictional I14 Security Policies and Risk Package. Confirm that it contains a governance charter, responsibility matrix, asset and BIA register, evidence-quality register, risk register, treatment plan, policy hierarchy, exception register, supplier review, metrics catalog, priority action plan, validation and closure criteria, reassessment triggers, technical report, leadership summary, reflection, and portfolio-safety statement.
Key Takeaways
Module Navigation