1. When facilitating the alignment of corporate governance and information security governance, which of the following is the MOST important role of an organization's security steering committee?
A) Obtaining support for the integration from business owners B) Obtaining approval for the information security budget C) Evaluating and reporting the degree of integration D) Defining metrics to demonstrate alignment
2. Which of the following is the PRIMARY responsibility of an information security governance committee?
A) Approving the purchase of information security technologies B) Approving the information security awareness training strategy C) Reviewing the information security strategy D) Analyzing information security policy compliance reviews
3. What is the MOST effective way to ensure security policies and procedures are up-to-date?
A) Verify security requirements are being identified and consistently applied. B) Align the organization's security practices with industry standards and best practice. C) Define and document senior management's vision for the direction of the security D) Prevent security documentation audit issues from being raised
4. Which of the following is the PRIMARY advantage of having an established information security governance framework in place when an organization is adopting emerging technologies?
A) An emerging technologies strategy would be in place B) A cost-benefit analysis process would be easier to perform C) An effective security risk management process is established D) End-user acceptance of emerging technologies has been established
5. From a risk management perspective, which of the following is MOST important to be tracked in continuous monitoring?
A) Number of prevented attacks B) Changes in the threat environment C) Changes in user privileges D) Number of failed logins
Leave a comment