Topic 1: Governance (Policy, Legal & Compliance)
When briefing senior management on the creation of a governance process, the MOST important aspect should be:
A.
information security metrics.
B.
knowledge required to analyze each issue.
C.
baseline against which metrics are evaluated.
D.
linkage to business area objectives.
linkage to business area objectives.
In accordance with best practices and international standards, how often is security awareness training provided to employees of an organization?
A.
High risk environments 6 months, low risk environments 12 months
B.
Every 12 months
C.
Every 18 months
D.
Every six months
Every 12 months
What is the main purpose of the Incident Response Team?
A.
Ensure efficient recovery and reinstate repaired systems
B.
Create effective policies detailing program activities
C.
Communicate details of information security incidents
D.
Provide current employee awareness programs
Ensure efficient recovery and reinstate repaired systems
A global health insurance company is concerned about protecting confidential information. Which of the following is of MOST concern to this organization?
A.
Compliance to the Payment Card Industry (PCI) regulations.
B.
Alignment with financial reporting regulations for each country where they operate.
C.
Alignment with International Organization for Standardization (ISO) standards.
D.
Compliance with patient data protection regulations for each country where they operate.
Compliance with patient data protection regulations for each country where they operate.
The PRIMARY objective for information security program development should be:
A.
Reducing the impact of the risk to the business.
B.
Establishing strategic alignment with bunsiness continuity requirements
C.
Establishing incident response programs.
D.
Identifying and implementing the best security solutions.
Reducing the impact of the risk to the business.
Page 3 out of 89 Pages |
Previous |