Exam 7: Security Management Practices
Exam 1: Introduction to the Management of Information Security139 Questions
Exam 2: Planning for Security123 Questions
Exam 3: Planning for Contingencies114 Questions
Exam 4: Information Security Policy133 Questions
Exam 5: Developing the Security Program133 Questions
Exam 6: Security Management Models120 Questions
Exam 7: Security Management Practices114 Questions
Exam 8: Risk Management: Identifying and Assessing Risk78 Questions
Exam 9: Risk Management: Controlling Risk105 Questions
Exam 10: Protection Mechanisms133 Questions
Exam 11: Personnel and Security133 Questions
Exam 12: Law and Ethics113 Questions
Select questions type
A(n)baseline is a "value or profile of a performance metric against which changes in the performance metric can be usefully compared." _________________________
(True/False)
4.7/5
(39)
Which of the following is NOT a goal of the NIST System Certification and Accreditation Project:
(Multiple Choice)
4.7/5
(40)
Best security practices (BSPs)balance the need for information access with the need for adequate protection while simultaneously demonstrating social responsibility.
(True/False)
4.8/5
(31)
During Phase 1 of the NIST performance measures development process,the organization identifies relevant ____ and their interests in information security measurement.
(Multiple Choice)
4.8/5
(42)
By looking at the paths taken by organizations similar to the one whose plan you are developing,known as benchmarking,the organization can follow the recommended or existing practices of a similar organization or industry-developed standards._________________________
(True/False)
4.8/5
(32)
Certification is defined as "the comprehensive evaluation of the technical and nontechnical security controls of an IT system to support the accreditation process that establishes the extent to which a particular design and implementation meets a set of specified security requirements.
(True/False)
4.9/5
(37)
The ____________________ standard is a model level of performance that demonstrates industrial leadership,quality,and concern for the protection of information.
(Short Answer)
4.9/5
(39)
The ____ standard is a model level of performance that demonstrates industrial leadership,quality,and concern for the protection of information.
(Multiple Choice)
4.8/5
(49)
In future certification and accreditation practices,NIST will focus less on certification and accreditation strategies,and more on ____.
(Multiple Choice)
5.0/5
(33)
The process of implementing a performance measures program recommended by NIST involves six phases.List them.
(Essay)
4.7/5
(36)
Implementing controls at an acceptable standard-and maintaining them-demonstrates that an organization has performed due diligence._________________________
(True/False)
4.8/5
(32)
NIST recommends the documentation of each performance measure in a customized format to ensure repeatability of measures development,tailoring,collection,and reporting activities.
(True/False)
4.8/5
(41)
In the future,NIST is replacing traditional Certification and Accreditation with authorization strategies and security control assessment.
(True/False)
4.8/5
(37)
It is no longer sufficient to simply assert effective information security; an organization must demonstrate that it is taking effective measures in the spirit of due diligence._________________________
(True/False)
4.8/5
(45)
One of the critical tasks in the measurement process is to assess and ____________________ what will be measured.
(Short Answer)
4.9/5
(36)
Organizations typically use three types of performance measures,including those that assess the impact of a(n)____________________ or other security event on the organization or its mission.
(Short Answer)
4.9/5
(32)
Production level statistics depend greatly on the number of systems and the number of users of those systems._________________________
(True/False)
4.9/5
(43)
The federal government prohibits the distribution of best security practices with organizations other than federal agencies._________________________
(True/False)
4.9/5
(40)
The benefits of using information security performance measures include "increasing ____________________ for information security performance; improving effectiveness of information security activities; demonstrating compliance with laws,rules,and regulations; and providing quantifiable inputs for resource allocation decisions."
(Short Answer)
4.8/5
(42)
Showing 41 - 60 of 114
Filters
- Essay(0)
- Multiple Choice(0)
- Short Answer(0)
- True False(0)
- Matching(0)