Exam 17: Human Resources Security

arrow
  • Select Tags
search iconSearch Question
flashcardsStudy Flashcards
  • Select Tags

Employee behavior is not a critical concern in ensuring the security of computer systems.

Free
(True/False)
4.7/5
(32)
Correct Answer:
Verified

False

The education and experience learning level provides the foundation for subsequent training by providing a universal baseline of key security terms and concepts.

Free
(True/False)
4.9/5
(31)
Correct Answer:
Verified

False

An employer cannot be held liable for negligent hiring if an employee causes harm to a third party while acting as an employee.

Free
(True/False)
4.8/5
(43)
Correct Answer:
Verified

False

_______ are ways for an awareness program to promote the security message to employees.

(Multiple Choice)
4.8/5
(39)

After security basics and literacy,training becomes focused on providing the knowledge,skills,and abilities specific to an individual's _______ relative to IT systems.

(Essay)
5.0/5
(28)

A capability set up for the purpose of assisting in responding to computer security-related incidents that involve sites within a defined constituency is called a ______.

(Multiple Choice)
5.0/5
(38)

Complying with regulations and contractual obligations is a benefit of security awareness,training,and education programs.

(True/False)
4.8/5
(39)

________ need training on the development of risk management goals,means of measurement,and the need to lead by example in the area of security awareness.

(Multiple Choice)
4.8/5
(40)

From a security point of view,which of the following actions should be done upon the termination of an employee?

(Multiple Choice)
4.7/5
(30)

In large and medium-sized organizations,a(n)_________ is responsible for rapidly detecting incidents,minimizing loss and destruction,mitigating the weaknesses that were exploited,and restoring computing services.

(Essay)
4.8/5
(39)

In general,a(n)________ program seeks to inform and focus an employee's attention on issues related to security within the organization.

(Essay)
4.8/5
(42)

Many companies incorporate specific e-mail and Internet use policies into the organization's security policy document.

(True/False)
4.9/5
(36)

Security awareness,training,and education programs may be needed to comply with regulations and contractual obligations.

(True/False)
4.7/5
(43)

Any action that threatens one or more of the classic security services of confidentiality,integrity,availability,accountability,authenticity,and reliability in a system constitutes a(n)________.

(Essay)
4.7/5
(36)

Awareness only communicates information security policies and procedures that need to be followed and does not provide the foundation for any sanctions or disciplinary actions imposed for noncompliance.

(True/False)
4.7/5
(37)

A(n)_______ is a characteristic of a piece of technology that can be exploited to perpetrate a security incident.

(Essay)
4.8/5
(30)

________ is the process of receiving,initial sorting,and prioritizing of information to facilitate its appropriate handling.

(Multiple Choice)
4.7/5
(30)

As part of their contractual obligation,employees should agree and sign the terms and conditions of their employment contract,which should state their and the organization's responsibilities for information security.

(True/False)
5.0/5
(29)

________ is explicitly required for all employees.

(Multiple Choice)
4.8/5
(39)

_______ is a benefit of security awareness,training,and education programs to organizations.

(Multiple Choice)
4.8/5
(33)
Showing 1 - 20 of 45
close modal

Filters

  • Essay(0)
  • Multiple Choice(0)
  • Short Answer(0)
  • True False(0)
  • Matching(0)