1. Which of the following is the MOST important reason for an organization to develop an information security governance program?
A) Establishment of accountability B) Compliance with audit requirements C) Monitoring of security incidents D) Creation of tactical solutions
2. The PRIMARY purpose of aligning information security with corporate governance objectives is to:
A) build capabilities to improve security processes. B) consistently manage significant areas of risk. C) identify an organization's tolerance for risk. D) re-align roles and responsibilities.
3. Which of the following is the MOST important consideration for designing an effective information security governance framework?
A) Defined metrics B) Continuous audit cycle C) Security policy provisions D) Security controls automation
4. The PRIMARY goal of information security governance to an organization is to:
A) align with business processes B) align with business objectives C) establish a security strategy D) manage security costs
5. Which of the following is the BEST way to integrate information security into corporate governance?
A) Engage external security consultants in security initiatives. B) Conduct comprehensive information security management training for key stakeholders. C) Ensure information security processes are part of the existing management processes. D) Require periodic security risk assessments be performed.
Leave a comment