Exam 3: Governance and Strategic Planning for Security

arrow
  • Select Tags
search iconSearch Question
flashcardsStudy Flashcards
  • Select Tags

Information security governance yields significant benefits.List five.

Free
(Essay)
4.8/5
(30)
Correct Answer:
Verified

1.An increase in share value for organizations
2.Increased predictability and reduced uncertainty of business operations by lowering information-security-related risks to definable and acceptable levels
3.Protection from the increasing potential for civil or legal liability as a result of information inaccuracy or the absence of due care
4.Optimization of the allocation of limited security resources
5.Assurance of effective information security policy and policy compliance
6.A firm foundation for efficient and effective risk management,process improvement,and rapid incident response
7.A level of assurance that critical decisions are not based on faulty information
8.Accountability for safeguarding information during critical business activities,such as
mergers and acquisitions,business process recovery,and regulatory response.

What is the first phase of the SecSDLC? 

Free
(Multiple Choice)
4.9/5
(33)
Correct Answer:
Verified

B

​The ISA 27014:2013 standard promotes five risk management processes,which should be adopted by the organization's executive ​management and its governing board.

Free
(True/False)
4.9/5
(31)
Correct Answer:
Verified

False

​A person or organization that has a vested interest in a particular aspect of the planning or operation of the organization is a stockbroker.

(True/False)
4.8/5
(38)

What is necessary for a top-down approach to the implementation of InfoSec to succeed?

(Essay)
4.9/5
(36)

Which of the following is a key advantage of the bottom-up approach to security implementation? 

(Multiple Choice)
4.7/5
(23)

Which of the following explicitly declares the business of the organization and its intended areas of operations? 

(Multiple Choice)
4.8/5
(38)

​The individual responsible for the assessment,management,and implementation of information-protection activities in the organization is known as a(n)____________.

(Multiple Choice)
4.9/5
(29)

​Individuals who control,and are therefore responsible for,the security and use of a particular set of information are known as ____________.

(Multiple Choice)
4.9/5
(33)

​ISO 27014:2013 is the ISO 27000 series standard for ____________.

(Multiple Choice)
4.7/5
(28)

​A senior executive who promotes the project and ensures its support,both financially and administratively,at the highest levels of the organization is needed to fill the role of a(n)____________ on a development team.

(Multiple Choice)
4.8/5
(25)

The ______________________ phase is the last phase of SecSDLC,but perhaps the most important.

(Short Answer)
4.8/5
(37)

​The individual accountable for ensuring the day-to-day operation of the InfoSec program,accomplishing the objectives identified by the CISO and resolving issues identified by technicians are known as a(n)____________.

(Multiple Choice)
5.0/5
(31)

According to the ITGI,what are the four supervisory tasks a board of directors should perform to ensure strategic InfoSec objectives are being met?

(Essay)
4.7/5
(38)

A 2007 Deloitte report found that valuable approach that can better align security functions with the business mission while offering opportunities to lower costs is ____________.

(Multiple Choice)
4.7/5
(42)

_________resources include people,hardware,and the supporting system elements and resources associated with the management of information in all its states.

(Short Answer)
4.9/5
(34)

According to the Corporate Governance Task Force (CGTF),which phase in the IDEAL model and framework lays the groundwork for a successful improvement effort? 

(Multiple Choice)
4.9/5
(34)

Which of the following is true about planning? 

(Multiple Choice)
4.9/5
(44)

​When using the Governing for Enterprise Security (GES)program,an Enterprise Security Program (ESP)should be structured so that governance activities are driven by the organization's executive management,select key stakeholders,as well as the ____________.

(Multiple Choice)
4.9/5
(35)

What is the values statement and what is its importance to an organization?

(Essay)
4.8/5
(37)
Showing 1 - 20 of 52
close modal

Filters

  • Essay(0)
  • Multiple Choice(0)
  • Short Answer(0)
  • True False(0)
  • Matching(0)