Exam 7: Security Management Practices

arrow
  • Select Tags
search iconSearch Question
flashcardsStudy Flashcards
  • Select Tags

One of the priorities in building an information security measures program is determining whether these measures will be macro-focus or micro-focus.

(True/False)
4.8/5
(29)

During Phase 2 of the NIST performance measures development process,the organization will identify and document the information security performance ____ that would guide security control implementation for the information security program of a specific information system.

(Multiple Choice)
4.9/5
(30)

One of the most popular of the many references that support the development of process improvement and performance measures is The Capability Maturity Model Integrated (CMMI)designed specifically to integrate an organization's process improvement activities across disciplines._________________________

(True/False)
4.8/5
(33)

One of the fundamental challenges in information security performance measurement is the definition of ____ security.

(Multiple Choice)
4.7/5
(25)

Performance measurement is an ongoing,continuous improvement operation._________________________

(True/False)
4.8/5
(40)

Security efforts that seek to provide a(n)acceptable level of performance in the protection of information are called recommended business practices or just best practices._________________________

(True/False)
4.9/5
(39)

It is seldom advisable to broadcast complex and nuanced metrics-based reports to large groups,unless ____.

(Multiple Choice)
4.9/5
(40)

Collecting project metrics may be even more challenging.Unless the organization is satisfied with a simple tally of who spent how many hours doing which tasks,it needs some mechanism to link the ____ of each project,in terms of loss control or risk reduction,to the resources consumed.

(Multiple Choice)
4.9/5
(39)

According to NIST SP 800-37,the first step in the security controls selection process is to ____.

(Multiple Choice)
4.9/5
(34)

Which of the following is NOT a question a CISO should be prepared to answer,about a performance measures program,according to Kovacich?

(Multiple Choice)
4.8/5
(31)

Information security performance management is the process of designing,implementing,and managing the use of the collected data elements called measures to determine the effectiveness of the overall security program.

(True/False)
4.8/5
(33)

When an organization applies statistical and quantitative forms of mathematical analysis to the data points collected to measure the activities and outcomes of the InfoSec program,it is using InfoSec ____________________.

(Short Answer)
4.9/5
(32)

The benefits of using information security performance measures include all but which of the following?

(Multiple Choice)
4.9/5
(27)

One of the most popular references for developing process improvement and performance measures is the ____ model from the Software Engineering Institute at Carnegie Mellon University.

(Multiple Choice)
4.9/5
(34)

A goal of 100 percent employee information security training in the training program would invalidate the continued collection of training measures._________________________

(True/False)
4.8/5
(42)

Security efforts that seek to provide a superior level of performance in the protection of information are referred to as ____________________.

(Short Answer)
4.7/5
(33)

In the future,NIST plans to replace accreditation with ____ and certification with ____.

(Multiple Choice)
4.9/5
(40)

A(n)____________________ is an external "value or profile of a performance metric against which changes in the performance metric can be usefully compared."

(Short Answer)
5.0/5
(39)

List the four factors critical to the success of an information security performance program,according to NIST SP 800-55.

(Essay)
4.8/5
(41)

Strong upper level management support is critical to the success of an information security performance program._________________________

(True/False)
4.9/5
(38)
Showing 21 - 40 of 114
close modal

Filters

  • Essay(0)
  • Multiple Choice(0)
  • Short Answer(0)
  • True False(0)
  • Matching(0)