GOVERNANCE - Risk Management Roles and responsibilites - Information Security Roles and Responsibilities

35 important questions on GOVERNANCE - Risk Management Roles and responsibilites - Information Security Roles and Responsibilities

What should drive projects

The achievement of business benefits

Which six elements are normally included in a feasibility study?

  1. Project Scope
  2. Current analysis
  3. Requirements
  4. Approach
  5. Evaluation
  6. Review


Who conducts the review of a feasibility study?

All stakeholders
  • Higher grades + faster learning
  • Never study anything twice
  • 100% sure, 100% understanding
Discover Study Smart

What is the main question in a business case for setting up and continuing a project?

Why should this project be undertaken?

What is meant by "stage gates" or "kill points" in a project?

Points at which the business case is formally reviewed to ensure it is still valid.

What is an essential monitoring tool to track the status of the security program and issues like compliance and emerging risk?

Consistent and reliable reporting

What is important to make senior management aware of the state of the information security program and governance issues?

Periodic formal reporting

What groups need to bee informed by routine communication channels?


  1. Senior management
  2. Business process owners
  3. Other management
  4. Employees

Who needs to establish acceptance and risk tolerance?

Board of directors

Who needs to ensure adequate regulatory compliance?

Board of directors

Who requires reporting of security effectiveness?

Board of directors


Who oversees a policy of knowledge management and resource utilization?

Board of directors

Who oversees a policy of assurance process integration?

Board of directors

What role requires monitoring and metrics for security activities

Executive management

What role ensures processes for knowledge capture and efficiency metrics?

Executive management

What role provides oversight of all assurance functions and plans for integration

Executive management

What role identifies emerging risk, promotes business unit security practices and identifies compliance issues?

Steering committee

What role reviews and advises on cost effectiveness of security activities needed to serve business functions?

Steering committee

What role reviews processes for knowledge capture and dissemination and utilization of resources?

Steering committee

What role identifies critical business processes and assurance providers?

Steering committee


What role provides direct assurance integration efforts?

Steering committee

What role develops the security strategy in alignment with business objectives?

CISO/ISM

What role oversees the security program and liaises with business process owners for ongoing alignment?

CISO/ISM

What role monitors and optimizes utilization, efficiency and effectiveness of security resources?

CISO/ISM

What role develops risk mitigation strategies?

CISO/ISM

What role enforces policy and regulatory compliance

CISO/ISM

What role develops, implements and reports monitoring metrics needed to support at the strategic, management and operational levels?

CISO/ISM

What role develops methods for knowledge capture and dissemination?

CISO/ISM

What role monitors and measures resource utilization and cost effectiveness?

CISO/ISM

What role ensures that gaps and overlaps are identified and addressed

CISO/ISM

What role promotes integration of assurance activities?

CISO/ISM

What role evaluates and reports on corporate risk management practices and results?

Audit

What role evaluates and reports on the comprehensives and effectiveness of program monitoring activities

Audit

What role evaluates and reports on the efficiency and utilization of resources?

Audit

What role evaluates and reports on integration and effectiveness of assurance processes?

Audit

The question on the page originate from the summary of the following study material:

  • A unique study and practice tool
  • Never study anything twice again
  • Get the grades you hope for
  • 100% sure, 100% understanding
Remember faster, study better. Scientifically proven.
Trustpilot Logo