GOVERNANCE - Compiled notes - Exam practise flash

40 important questions on GOVERNANCE - Compiled notes - Exam practise flash

Which interconnection connects the people and organization design and strategy elements in the business model for information security (BMIS)

Culture

Which role should review and provide input to security strategy and requirements for effective business support

Steering commitee

Which role identifies emerging risks and identifies compliance issues

Steering commitee
  • Higher grades + faster learning
  • Never study anything twice
  • 100% sure, 100% understanding
Discover Study Smart

Which interconnection connects the Process and Technology elements in the business model for information security (BMIS)

Enablement and support

Which role monitors regulatory compliance

Executive management or senior management

Which component in GRC is the process that records and monitors the policies, procedures and controls needed to ensure that policies and standards are followed

Compliance

Which main personnel participants should begin the process of the information security strategy development


Senior management, steering committee and CISO or information security manager

Which role establishes the acceptable risk and tolerances

Board of directors

From which document is the business case usually derived

Feasibility study

Which role should institute processes to integrate security with business objectives

Executive management or senior management

To which group should the information security manager present an overall strategy for information security to obtain approval

Senior management

What are the 4 components of the GRC capability Model


Learn
Align
Perform
Review

Which roles are responsible for due care and managing risk

The board and senior management

What is the purpose of a RACI chart

To define the various roles associated with aspects of an information security program

Which interconnection connects People and Process in BMIS

Emergence

Which interconnection connects People and Technology in BMIS

Human factors

What is the difference between a role and a responsibilty


A role is a designation assigned by virtue of job function
Responsibility is a is a description of some function related to a role

Which role should demonstrate alignment of security and business objectives

Board of directors

Which role ensures that risk and business impact assessments are conducted

CISO

What is meant by acceptable risk or risk appetite

The amount of risk an entity is willing to accept in pursuit of its mission

Which term is used for the protection measures that directly reduce a vulnerability or threat

Countermeasures

What are the four elements of the business model for information security


Organization design and strategy
People
Process
Technology

What are the 5 elements of COBIT 5


  1. Meeting stakeholder needs
  2. Covering the enterprise end-to-end
  3. Applying a single, integrated framework
  4. Enabling a holistic approach
  5. Separating governance from management

What is the purpose of a business case

To capture the business reasoning for initiating a project or task

Which role should evaluate and report on the degree of alignment

Auditors

According to ISACA, what are the basic six outcomes of a security program that is developed from information security governance


Strategic Alignment
Risk Management
Value delivery
Resource Optimization
Performance measurement

What is the first step in establishing information security governance

Senior management determines the outcomes it wants from the information security program

Which component in GRC is the responsibly of senior management and the board of directors, and focuses on creating mechanisms to ensure that personnel follow established processes and policies?

Governance


What is the best way to convince senior management to do more than just comply with regulations?

Pentest

Which enterprise architectural framework enables communication of information to personnel in a manner that is most useful to each group's responsibilities?

Zachman

Which outcome of security governance ensures that the information security initiative supports organizational objectives?

Strategic alignment

What is the biggest challenge for a CISO when doing a security assessment to determine state of security program in a company

Identifying assets

Who are responsible for having proper security controls in place for systems

System Owners

Who are responsible for ensuring systems are included in relevant policies?

System owners

Which role is responsible for overseeing that all security project align with the information security strategy?


Steering committee

Which organizational role is responsible for protecting the data they are responsible

Information owners

Where is information security governance in part derived from?

Corporate governance


What are the initial requirements for developing a security strategy?

Well defined objectives and an understanding of the current risk conditions

Fluctuating value of an asset. Where should the expenditure for security be based on?

Average of asset

2 Companies merge. Different retention periods. Regulation & Internal. Which retention period does need to be kept after the merger?

Longest

The question on the page originate from the summary of the following study material:

  • A unique study and practice tool
  • Never study anything twice again
  • Get the grades you hope for
  • 100% sure, 100% understanding
Remember faster, study better. Scientifically proven.
Trustpilot Logo