option
Questions
ayuda
daypo
search.php

Information Security Governance

COMMENTS STATISTICS RECORDS
TAKE THE TEST
Title of test:
Information Security Governance

Description:
ISG MSIC 1

Creation Date: 2026/09/02

Category: Others

Number of questions: 50

Rating:(0)
Share the Test:
Nuevo ComentarioNuevo Comentario
New Comment
NO RECORDS
Content:

Which of the following is the BEST way to demonstrate the alignment of the information security strategy with the business strategy?. Show the relationship between information security goals and corporate goals. Compare the allocated budget for business with the information security budget. Present senior management's approval of information security policies. Provide evidence that information security is included in the change management process.

Which of the following is the BEST way to ensure that organizational security policies comply with data security regulatory requirements?. Obtain annual sign-off from executive management. Align the policies to the most stringent global regulations. Send the policies to stakeholders for review. Outsource compliance activities.

Which of the following is MOST important for building a robust information security culture within an enterprise?. Mature information security awareness training across the organization. Security controls embedded within the development and operation of the IT environment. Senior management approval of information security policies. Strict enforcement of employee compliance with organizational security policies.

Embedding security responsibilities into job descriptions is important PRIMARILY because it: Simplifies development of the security awareness program. Aligns security to the human resources (HR) function. Supports access management.

Which of the following is MOST likely to be included in an enterprise security policy?. Definition of responsibilities. Retention Schedules. System access specfications. Organizational Risk.

Which of the following BEST enables the integration of information security governance into corporate governance?. Senior Management approval of the information security strategy. Clear lines of authority across the organization. An information security steering committee with business representation. Well-documented information security policies and standards.

Which of the following is the MOST important consideration when evaluating the performance of existing security controls?. Interviewing control owners to accurately collect metrics data. Establishing testing scenarios based on international data. Selecting testing methods that match the purpose of the testing. Obtaining senior management support to facilitate testing.

When scoping a risk assessment, assets need to be classified by: Sensitivity and criticality. Likelihood and impact. Threats and opportunities. Redundancy and recoverability.

Which of the following is the PRIMARY responsibility of an information security steering committee composed of management representation from business units?. Oversee the execution of the information security strategy. Perform business impact analysis. Manage the implementation of the information security plan. Monitor the treatment of the information security risk.

When defining and communicating roles and responsibilities between an enterprise and cloud service provider, which of the following situations would present the GREATEST risk to the enterprise's ability to ensure information risk is managed appropriately?. The service agreement uses a custom-developed RACI instead of an industry standard RACI to document responsibilites. The organization believes the provider accepted responsibility for issues affecting security that the provider did not accept. The organization and provider identified multiple information security responsibilities that neither party was planning to provide. The service agreement results in unnecessary duplication of effort because shared responsibilities have not been clearly defined.

An security manager determines there are a significant number of exceptions to a newly released industry-required security standard. Which of the following should be done NEXT?. Document risk acceptances. Conduct an information security audit. Assess the consequence of noncompliance. Revise the organization's security policy.

Which of the following is MOST important to the effectiveness of an information security program?. The program is aligned to legal and regulatory requirements. The program is aligned to a security control framework. Annual audits of the program are conducted. Users are trained on security policies and procedures.

Which of the following is the MOST effective approach to ensure IT processes are performed in compliance with the information security policies?. Ensuring that key controls are embedded in the processes. Providing information security policy training to the process owners. Allocating sufficient resources. Identifying risks in the processes and managing those risks.

Which of the following should an information security manager do FIRST when assessing conflicting requirements between the global enterprise's security standards and local regulations?. Conduct a gap analysis against local regulations. Perform a cost-benefit analysis of compliance. Create a local version of the organizational standards. Prioritize the organizational standards over local regulations.

Which of the following is MOST helpful for retaining the support of executive management for an information security program?. Forming an information security steering committee to provide oversight of the program. Providing regular performance reports on the effectiveness of the program. Including satisfaction with information security in employee engagement surveys. Developing business cases to justify continued expenses for security awareness.

An enterprise is performing an annual review of its risk landscape. Which of the following anticipated changes will have the MOST significant impact on the information security strategy?. The renewal and renegotiation of the organization's contract with its managed security services provider. Migration of personal data to a new database system on a different server platform. The expansion to an international location with unfamiliar security and privacy regulations. Replacement of the aging enterprise-wide core firewall infrastructure with a new solution from a different vendor.

To ensure the information security of outsourced IT services, which of the following is the MOST critical due diligence activity?. Assess the level of security awareness of the service provider. Review a recent independent audit report of the service provider. Review samples of service level reports from the service provider. Request the service provider comply with information security policy.

Which of the following is MOST important for guiding the development and management of a comprehensive information security program?. Adopting information security program management best practices. Aligning the organization's business objectives with IT objectives. Establishing and maintaining an information security governance framework. Implementing policies and procedures to address the information security strategy.

An external security audit has reported multiple instances of control noncompliance. Which of the following is MOST important for the information security manager to communicate to senior management?. The impact of noncompliance on the organization's risk profile. An accountability report to initiate remediation activities. Control owner responses based on a root cause analysis. A plan for mitigating the risk due to noncompliance.

Which of the following BEST enables an organization to provide ongoing assurance that legal and regulatory compliance requirements can be met?. Engaging external experts to provide guidance on changes in compliance requirements. Assigning the operations manager accountability for meeting compliance. Embedding compliance requirements within operational processes. Performing periodic audits for compliance with legal and regulatory requirements.

An information security manager of an e-commerce business is reviewing the results of a business continuity plan (BCP) review. Which of the following findings should be the MOST immediate concern?. The cost of a recent recovery test exceeded budget expectations. The annual business impact analysis (BIA) has been delayed. The business continuity plan (BCP) has not been recently tested. The recovery time objective (RTO) was not met during a recent power outage.

Which of the following is MOST important to determine following the discovery and eradication of a malware attack?. The creator of the malware. The malware entry path. The type of malware involved. The method of detecting the malware.

The resilience requirements of an application are BEST determined by: a cost-benefit analysis. a threat assessment. a business impact analysis (BIA). a risk assessment.

When scoping a risk assessment, assets need to be classified by: sensitivity and criticality. likelihood and impact. threats and opportunities. redundancy and recoverability.

Which of the following is the PRIMARY objective of integrating information security governance into corporate governance?. To align security goals with the information security program. To ensure the business supports information security goals. To adequately safeguard the business in achieving its mission. To obtain management commitment for sustaining the security program.

Which of the following is the BEST way to determine if a recent investment in access control software was successful?. Senior management acceptance of the access control software. A comparison of security incidents before and after software installation. A business impact analysis (BIA) of the systems protected by the software. A review of the number of key risk indicators (KRIs) implemented for the software.

An enterprise has decided to procure security services from a third-party vendor to support its information security program. Which of the following is MOST important to include in the vendor selection criteria?. The maturity of the vendor's internal control environment. Feedback from the vendor's previous clients. Alignment of the vendor's business objectives with enterprise security goals. Penetration testing against the vendor's network.

Which of the following is the BEST way to demonstrate the alignment of the information security strategy with the business strategy?. Show the relationship between information security goals and corporate goals. Compare the allocated budget for business with the information security budget. Present senior management's approval of information security policies. Provide evidence that information security is included in the change management process.

To gain a clear understanding of the impact that a new regulatory requirement will have on an organization's information security controls, an information security manager should FIRST : conduct a cost-benefit analysis. conduct a risk assessment. interview senior management. perform a gap analysis.

The information security manager of a multinational organization has been asked to consolidate the information security policies of its regional locations. Which of the following would be of GREATESTconcern?. Varying threat environments. Disparate reporting lines. Conflicting legal requirements. Differences in work culture.

When management changes the enterprise business strategy, which of the following processes should be used to evaluate the existing information security controls as well as to select new information security controls?. Access control management. Change management. Configuration management. Risk management.

Which of the following is the BEST way to build a risk-aware culture?. Periodically change risk awareness messages. Ensure that threats are communicated organization-wide in a timely manner. Periodically test compliance with security controls and post results. Establish incentives and a channel for staff to report risks.

An organization has purchased a security information and event management (SIEM) tool. Which of the following is MOST important to consider before implementation?. Controls to be monitored. Reporting capabilities. The contract with the SIEM vendor. Available technical support.

What would be an information security manager's BEST recommendation upon learning that an existing contract with a third party does not clearly identify requirements for safeguarding the organization's critical data?. Cancel the outsourcing contract. Transfer the risk to the provider. Create an addendum to the existing contract. Initiate an external audit of the provider's data center.

When establishing classifications of security incidents for the development of an incident response plan, which of the following provides the MOST valuable input?. Business impact analysis (BIA) results. Recommendations from senior management. The business continuity plan (BCP). Vulnerability assessment results.

An information security manager has been asked to determine whether an information security initiative has reduced risk to an acceptable level. Which of the following activities would provide the BEST information for the information security manager to draw a conclusion?. Initiating a cost-benefit analysis of the implemented controls. Performing a risk assessment. Reviewing the risk register. Conducting a business impact analysis (BIA).

Which of the following is MOST important to include in a post-incident report?. Forensic analysis results. List of potentially compromised assets. Root cause analysis. Service level agreements.

An security manager of an e-commerce business is reviewing the results of a business continuity plan (BCP) review. Which of the following findings should be the MOST immediate concern?. The cost of a recent recovery test exceeded budget expectations. The annual business impact analysis (BIA) has not been recently tested. The business continuity plan (BCP) has not been recently tested. The recovery time objective (RTO) was not met during a recent power outage.

Which of the following is MOST important to determine following the discovery and eradication of a malware attack?. The creator of the malware. The malware entry path. The type of malware involved. The method detecting the malware.

Which of the following is the MOST important consideration when developing information security objectives?. They are regularly reassessed and reported to stakeholders. They are approved by the IT governance function. They are clear and can be understood by stakeholders. They are identified using global security frameworks and standards.

Which of the following is the MOST effective approach for determining whether an organization's information security program supports the information security strategy?. Ensure resources meet information security program needs. Audit the information program to identify deficiencies. Identify gaps impacting information security strategy. Develop key performance (KPIs) of information security.

Which of the following should be the PRIMARY focus of a status report on the information security program to senior management?. Confirming the organization complies with security policies. Verifying security costs do not exceed the budget. Demonstrating risk is managed at the desired level. Providing evidence that resources are performing as expected.

Which of the following should be an information security managers MOST important consideration when determining if an information asset has been classified appropriately?. Value to the business. Security Policy requirements. Ownership of information. Level of protection.

Which of the following BEST enables the deployment of consistent security throughout international branches within a multinational organization?. Remediation of Audit findings. Decentralization of security governance. Establishment of security governance. Maturity if security processes.

An information security manager discovers that the organization's new information security policy is not being followed across all departments. Which of the following should be of GREATEST concern to the information security manager?. Business unit management has not emphasized the importance of the new policy. Different communication methods may be required for each business unit. The wording of the policy is not tailored to the audience. The corresponding controls are viewed as prohibitive to business operations.

Which of the following is the MOST important reason for performing a cost- benefit analysis when implementing a security control?. To ensure that the mitigation effort does not exceed the asset value. To ensure benefits are aligned with business strategies. To present a realistic information security budget. To justify information security program activities.

The use of a business case to obtain funding for an information security investment is MOST effective when the business case: Relates the investment to the organization's strategic plan. Realigns information security objectives to organizational strategy. Articulates management's intent and information security directives in clear language. Translates information security policies and standards into business requirements.

An information security manager MUST have an understanding of the enterprise's business goals to: Relate information security to change management. Develop an information security strategy. Develop operational procedures. Define key performance indicators (KPIs).

What is the BEST reason to keep information security policies separate from procedures?. To keep policies from having to be changed too frequently. To ensure that individual documents do not contain conflicting information. To keep policy documents from becoming too large. To ensure policies receive the appropriate approvals.

To set security expectations across the enterprise, it is MOST important for the information security policy to be regularly reviewed and endorsed by: Security admin. Senior management. The chief information security officer (CISO). The IT steering committee.

Report abuse