Exam 15: IT Security Controls, Plans, and Procedures

arrow
  • Select Tags
search iconSearch Question
flashcardsStudy Flashcards
  • Select Tags

Physical access or environmental controls are only relevant to areashousing the relevant equipment.

(True/False)
4.9/5
(38)

The recommended controls need to be compatible with theorganization's systems and policies.

(True/False)
4.9/5
(43)

Incident response is part of the ________ class of security controls.

(Short Answer)
4.8/5
(36)

An IT security plan should include details of _________.

(Multiple Choice)
4.9/5
(35)

Management controls refer to issues that management needs to address.

(True/False)
4.8/5
(37)

_______ controls are pervasive, generic, underlying technical IT security capabilities that are interrelated with, and used by, many other controls.

(Multiple Choice)
4.9/5
(34)

_________ controls focus on preventing security beaches from occurring by inhibiting attempts to violate security policies or exploit a vulnerability.

(Short Answer)
4.8/5
(31)

_______ controls focus on security policies, planning, guidelines, and standards that influence the selection of operational and technical controls to reduce the risk of loss and to protect the organization's mission.

(Multiple Choice)
4.9/5
(40)

The IT security management process ends with the implementation ofcontrols and the training of personnel.

(True/False)
4.8/5
(37)

The three steps for IT security management controls and implementation are: prioritize risks, respond to risks, and __________ .

(Short Answer)
4.9/5
(33)

_______ management is the process used to review proposed changes to systems for implications on the organization's systems and use.

(Short Answer)
4.7/5
(36)

Once in place controls cannot be adjusted, regardless of the results ofrisk assessment of systems in the organization.

(True/False)
4.7/5
(36)

A contingency plan for systems critical to a large organization would be _________ than that for a small business.

(Multiple Choice)
4.9/5
(42)

The objective of the ________ control category is to avoid breaches of any law, statutory, regulatory, or contractual obligations, and of any security requirements.

(Multiple Choice)
4.9/5
(39)

Contingency planning falls into the _________ class of security controls.

(Short Answer)
4.9/5
(48)

The implementation process is typically monitored by the organizational ______.

(Multiple Choice)
4.9/5
(36)

Water damage protection is included in security controls.

(True/False)
5.0/5
(38)

All controls are applicable to all technologies.

(True/False)
4.9/5
(42)

It is likely that the organization will not have the resources toimplement all the recommended controls.

(True/False)
4.8/5
(38)

An IT security ________ helps to reduce risks.

(Multiple Choice)
4.9/5
(40)
Showing 21 - 40 of 45
close modal

Filters

  • Essay(0)
  • Multiple Choice(0)
  • Short Answer(0)
  • True False(0)
  • Matching(0)