GRC & Compliance Quiz
Practice questions on EU regulations and security frameworks, tagged by chapter, with explanations cited to the primary text, per-chapter scores and a flashcard mode. Six topics so far — DORA, GDPR, NIS2, the Cyber Resilience Act, ISO/IEC 27001 and the NIST CSF 2.0 — with more as the community writes them.
Cyber Resilience Act — Regulation (EU) 2024/2847. 6 chapters.
Digital Operational Resilience Act — Regulation (EU) 2022/2554. 5 chapters.
General Data Protection Regulation — Regulation (EU) 2016/679. 6 chapters.
ISO/IEC 27001 — Information security management systems — ISO/IEC 27001:2022 (+ the ISO/IEC 27000 family). 7 chapters.
NIS2 Directive — network & information security — Directive (EU) 2022/2555. 6 chapters.
NIST Cybersecurity Framework 2.0 — NIST CSWP 29 (26 February 2024). 6 chapters.
NIST SP 800-53 Rev. 5 — Security & Privacy Controls — NIST SP 800-53 Rev. 5 (September 2020). 6 chapters.
Banks grow one cited question at a time. Studying a regulation or framework not yet here, and willing to write a few questions with article or clause references? Tell us.
Runs entirely in your browser: banks ship as static files, answers are scored locally, and nothing is sent anywhere. No session history is kept unless you tick “Remember my last score”, which uses the site's local persistence layer (see Your local data). Put the rules into practice with the working tools on the GRC Hub, and look terms up in the Glossary.