CISM Certification Domain 1: Information Security Governance Video Boot Camp 2019 - Policies, procedures, guidelines, an

CISM Certification Domain 1: Information Security Governance Video Boot Camp 2019 - Policies, procedures, guidelines, an

Assessment

Interactive Video

Information Technology (IT), Architecture

University

Hard

Created by

Quizizz Content

FREE Resource

The video tutorial covers the integration of policies, standards, guidelines, procedures, and baselines in professional settings. It emphasizes the importance of training and awareness to mitigate security risks posed by users. The tutorial also discusses security measures throughout the employee lifecycle, including background checks and NDAs. Additionally, it highlights the need for stringent security practices when dealing with vendors and outsourcing. Finally, it suggests engaging methods for security training, such as competitions and quizzes, to ensure effective learning.

Read more

7 questions

Show all answers

1.

MULTIPLE CHOICE QUESTION

30 sec • 1 pt

What is the primary characteristic of policies in a security framework?

They are optional and vendor-specific.

They provide specific step-by-step instructions.

They are mandatory and high-level.

They are non-mandatory and flexible.

2.

MULTIPLE CHOICE QUESTION

30 sec • 1 pt

Which of the following is true about guidelines?

They are used to create baselines.

They are mandatory and must be followed.

They provide specific vendor instructions.

They are non-mandatory and offer recommendations.

3.

MULTIPLE CHOICE QUESTION

30 sec • 1 pt

What is the main goal of security awareness?

To provide knowledge that may or may not be used.

To change user behavior through understanding.

To ensure compliance with all policies.

To document security procedures.

4.

MULTIPLE CHOICE QUESTION

30 sec • 1 pt

Why is it important to engage employees during security training?

To ensure they memorize all security policies.

To make sure they attend the training sessions.

To reduce the number of training sessions required.

To encourage active participation and retention.

5.

MULTIPLE CHOICE QUESTION

30 sec • 1 pt

What is an administrative security control mentioned in the video?

Encrypting sensitive data.

Implementing firewalls.

Conducting background checks.

Installing antivirus software.

6.

MULTIPLE CHOICE QUESTION

30 sec • 1 pt

What should be done when terminating an employee to ensure security?

Discuss termination with their colleagues.

Allow them to access data for a grace period.

Turn off their access immediately after termination.

Notify them a week in advance.

7.

MULTIPLE CHOICE QUESTION

30 sec • 1 pt

Why is it important to manage vendor access carefully?

To avoid having to conduct background checks.

To allow them unrestricted access to data.

To reduce the cost of security measures.

To ensure they follow the same security standards.