Which of the following would BEST ensure the success of information security governance within an organization?
A. Steering committees approve security projects
B. Security policy training provided to all managers
C. Security training available to all employees on the intranet
D. Steering committees enforce compliance with laws and regulations
Acceptable risk is achieved when:
A. residual risk is minimized.
B. transferred risk is minimized.
C. control risk is minimized.
D. inherent risk is minimized.
Which of the following is MOST important to the success of an information security program?
A. Security' awareness training
B. Achievable goals and objectives
C. Senior management sponsorship
D. Adequate start-up budget and staffing
A message* that has been encrypted by the sender's private key and again by the receiver's public key achieves:
A. authentication and authorization.
B. confidentiality and integrity.
C. confidentiality and nonrepudiation.
D. authentication and nonrepudiation.
Management has announced the acquisition of a new company. The information security manager of parent company is concerned that conflicting access rights may cause critical information to be exposed during the integration of the two companies.
To BEST address this concern, the information security manager should:
A. escalate concern for conflicting access rights to management.
B. implement consistent access control standards.
C. review access rights as the acquisition integration occurs.
D. perform a risk assessment of the access rights.
Which of the following needs to be established between an IT service provider and its clients to the BEST enable adequate continuity of service in preparation for an outage?
A. Data retention policies
B. Server maintenance plans
C. Recovery time objectives
D. Reciprocal site agreement
The BEST way to ensure that security settings on each platform are in compliance with information security policies and procedures is to:
A. perform penetration testing.
B. establish security baselines.
C. implement vendor default settings.
D. link policies to an independent standard.
Which of the following is a PRIMARY security responsibility of an information owner?
A. Deciding what level of classification the information requires
B. Testing information classification controls
C. Maintaining the integrity of data in the information system
D. Determining the controls associated with information classification
Which of the following should be the information security manager's NEXT step following senior management approval of the information security strategy?
A. Develop a security policy.
B. Develop a budget.
C. Perform a gap analysis.
D. Form a steering committee.
An organization's security policy is to disable access to USB storage devices on laptops and desktops.
Which of the following is the STRONGEST justification for granting an exception to the policy?
A. The benefit is greater than the potential risk.
B. USB storage devices are enabled based on user roles.
C. Users accept the risk of noncompliance.
D. Access is restricted to read-only.