1. When establishing an information security governance framework, it is MOST important for an information security manager to understand:
A) the regulatory environment. B) information security best practices. C) the corporate culture. D) risk management techniques.
2. Which of the following is a PRIMARY responsibility of the information security governance function?
A) Defining security strategies to support organizational programs B) Ensuring adequate support for solutions using emerging technologies C) Fostering a risk-aware culture to strengthen the information security program D) Advising senior management on optimal levels of risk appetite and tolerance
3. Which of the following is the MOST important requirement for the successful implementation of security governance?
A) Implementing a security balanced scorecard B) Performing an enterprise-wide risk assessment C) Mapping to organizational strategies D) Aligning to an international security framework
4. A large organization is in the process of developing its information security program that involves working with several complex organizational functions. Which of the following will BEST enable the successful implementation of this program?
A) Security governance B) Security policy C) Security metrics D) Security guidelines
5. Which of the following is a PRIMARY responsibility of an information security governance committee?
A) Analyzing information security policy compliance reviews B) Approving the purchase of information security technologies C) Reviewing the information security strategy D) Approving the information security awareness training strategy
Leave a comment