Exam 7: Security Management Practices

arrow
  • Select Tags
search iconSearch Question
flashcardsStudy Flashcards
  • Select Tags

A(n)baseline is a "value or profile of a performance metric against which changes in the performance metric can be usefully compared." _________________________

(True/False)
4.7/5
(39)

Which of the following is NOT a goal of the NIST System Certification and Accreditation Project:

(Multiple Choice)
4.7/5
(40)

Best security practices (BSPs)balance the need for information access with the need for adequate protection while simultaneously demonstrating social responsibility.

(True/False)
4.8/5
(31)

During Phase 1 of the NIST performance measures development process,the organization identifies relevant ____ and their interests in information security measurement.

(Multiple Choice)
4.8/5
(42)

By looking at the paths taken by organizations similar to the one whose plan you are developing,known as benchmarking,the organization can follow the recommended or existing practices of a similar organization or industry-developed standards._________________________

(True/False)
4.8/5
(32)

Certification is defined as "the comprehensive evaluation of the technical and nontechnical security controls of an IT system to support the accreditation process that establishes the extent to which a particular design and implementation meets a set of specified security requirements.

(True/False)
4.9/5
(37)

The ____________________ standard is a model level of performance that demonstrates industrial leadership,quality,and concern for the protection of information.

(Short Answer)
4.9/5
(39)

The ____ standard is a model level of performance that demonstrates industrial leadership,quality,and concern for the protection of information.

(Multiple Choice)
4.8/5
(49)

Good security now is better ____.

(Multiple Choice)
4.8/5
(39)

In future certification and accreditation practices,NIST will focus less on certification and accreditation strategies,and more on ____.

(Multiple Choice)
5.0/5
(33)

The process of implementing a performance measures program recommended by NIST involves six phases.List them.

(Essay)
4.7/5
(36)

Implementing controls at an acceptable standard-and maintaining them-demonstrates that an organization has performed due diligence._________________________

(True/False)
4.8/5
(32)

NIST recommends the documentation of each performance measure in a customized format to ensure repeatability of measures development,tailoring,collection,and reporting activities.

(True/False)
4.8/5
(41)

In the future,NIST is replacing traditional Certification and Accreditation with authorization strategies and security control assessment.

(True/False)
4.8/5
(37)

It is no longer sufficient to simply assert effective information security; an organization must demonstrate that it is taking effective measures in the spirit of due diligence._________________________

(True/False)
4.8/5
(45)

One of the critical tasks in the measurement process is to assess and ____________________ what will be measured.

(Short Answer)
4.9/5
(36)

Organizations typically use three types of performance measures,including those that assess the impact of a(n)____________________ or other security event on the organization or its mission.

(Short Answer)
4.9/5
(32)

Production level statistics depend greatly on the number of systems and the number of users of those systems._________________________

(True/False)
4.9/5
(43)

The federal government prohibits the distribution of best security practices with organizations other than federal agencies._________________________

(True/False)
4.9/5
(40)

The benefits of using information security performance measures include "increasing ____________________ for information security performance; improving effectiveness of information security activities; demonstrating compliance with laws,rules,and regulations; and providing quantifiable inputs for resource allocation decisions."

(Short Answer)
4.8/5
(42)
Showing 41 - 60 of 114
close modal

Filters

  • Essay(0)
  • Multiple Choice(0)
  • Short Answer(0)
  • True False(0)
  • Matching(0)