Acceptable levels of information security risk should be determined by:
A. legal counsel.
B. security management.
C. external auditors.
D. die steering committee.
Which of the following is the MOST important consideration for designing an effective information security governance framework?
A. Defined metrics
B. Continuous audit cycle
C. Security policy provisions
D. Security controls automation
Which of the following is the PRIMARY prerequisite to implementing data classification within an organization?
A. Defining job roles
B. Performing a risk assessment
C. Identifying data owners
D. Establishing data retention policies
An information security organization should PRIMARILY:
A. support the business objectives of the company by providing security-related support services.
B. be responsible for setting up and documenting the information security responsibilities of the information security team members.
C. ensure that the information security policies of the company are in line with global best practices and standards.
D. ensure that the information security expectations are conveyed to employees.
Which of the following metrics would provide management with the MOST useful information about the progress of a security awareness program?
A. Increased number of downloads of the organization's security policy
B. Increased reported of security incidents
C. Completion rate of user awareness training within each business unit
D. Decreased number of security incidents
An organization has implemented an enterprise resource planning (ERP) system used by 500 employees from various departments. Which of the following access control approaches is MOST appropriate?
A. Rule-based
B. Mandatory
C. Discretionary
D. Role-based
What is the PRIMARY goal of an incident management program?
A. Minimize impact to the organization.
B. Contain the incident.
C. Identify root cause.
D. Communicate to external entities.
Which of the following BEST determines an information asset's classification?
A. Value of the information asset in the marketplace
B. Criticality to a business process
C. Risk assessment from the data owner
D. Cost of producing the information asset
Reviewing which of the following would be MOST helpful when a new information security manager is developing an information security strategy for a non-regulated organization?
A. Management's business goals and objectives
B. Strategies of other non-regulated companies
C. Risk assessment results
D. Industry best practices and control recommendations
When deciding to move to a cloud-based model, the FIRST consideration should be:
A. storage in a shared environment.
B. availability of the data.
C. data classification.
D. physical location of the data.