WorksheetsLesson 4 Roles and Responsibilities
Total questions: 28
Worksheet time: 21mins
When putting together Board-Level metrics, which guiding principle is most important?
Show relative performance against peers
Indicate impact on business operations, costs, market share, etc
Be concise. Avoid information overload
Enable discussion and dialogue
When communicating with the Board and Executives, what fundamental things should they always know?
Highest priorities and timeline of completion
Future state and cost of fixing it
Current state and the roadmap
Future state and when we will get there.
As a vCISO, communicating with Shareholders becomes an important part of the job. Which question(s) enhance that conversation?
How do our cybersecurity-related disclosures compare to our competitors and peers?
How do we describe cybersecurity risk management activities?
Does cybersecurity appear in areas of expertise for one or more directors' biograpies?
All of the above
Boords should have adequate access to cybersecurity expertise, and discussions about (a) should be given regular time on board meeting agendas.
There are many ways to build a better relationship with the security team and the CISO but the one that can have the most impact is....
Make sure they know everything about you professionally and personally
Spend time with the security team outside the boardroom
Attend meetings
Make the rules and hold everyone accountable to follow them
What are the basic responsibilities of Board of Directors? Click all that apply.
Hire, monitor and evaluate the IT Manager
Provide financial oversight
Establish vision, mission and purpose.
Create Security Risk plan.
Ensure legal compliance and ethical integrity
True or False. It has become clear that boards need stronger foundations to govern cyber risks effectively.
True
False
True or False. The IT leadership is responsible to set the tone and define how the organization handles cybersecurity.
True
False
Choose all that apply. Cyber-resilient organizations:
Encourage systemic resilience and collaboration
Assure cybersecurity expertise is incorporated into board governance.
Align organizational design with cybersecurity
Understand economic drives and the impact of cyber risk.
All of the above.
What is NACD?
(a)
NACD focuses on these 5 core principals:
1. Organizational strategic risk
2. Legal and disclosure implications
3. Oversee structure and access to expertise
4. Framework to manage policy
5. Measuring cybersecurity
1. Cybersecurity as a strategic risk
2. Legal implications
3. Oversee structure and access to expertise
4. Framework to manage policy
5. Measuring and reporting cybersecurity
1. Cybersecurity as a strategic risk
2. Legal and disclosure implications
3. Oversee structure and access to expertise
4. Framework to manage cyber risk
5. Measuring and reporting cybersecurity
1. Cybersecurity as a strategic risk
2. Disclosure implications
3. Oversee structure and access to expertise
4. Framework to manage cyber risk
5. Reporting cybersecurity
None of the Above
Questions to enhance communications with shareholders. Select all that apply.
How do our cybersecurity-related disclosures compare to those of our industry peers and competitors?
Do we have any cybersecurity experts on the board or within 1 or more directors?
How would you describe your cybersecurity budget?
Is cybersecurity included in the company's list of risk factors?
Board oversight on the structure and access to expertise is an important part of their role. Choose the best selection(s) on way(s) the board can build better relationships with the security team and the CISO.
Understand the CISO's role and mandate.
Spend time with the security team outside the boardroom.
Assess how the CISO and security team collaborate with other departments and stakeholders.
All of the above.
Managers/Directors have governance responsibilities to carry out. All of these are important but which three are most important to get right first?
1. Establish and maintain an organization-wide cybersecurity policy that's informed by standards.
2. Define roles and responsibilities for all personnel involved in cybersecurity.
3. Check that cybersecurity policies, standards, and mechanisms are uniform throughout the organization.
1. Appoint a CISO or vCISO.
2. Ensure that person has a clear line of communication to leadership and the board as it relates to threats.
3. Maintain a regular invitation to that person to brief senior management.
1. Appoint a CISO or vCISO.
2. Ensure that person has a clear line of communication to you and the board as it relates to threats.
3. Establish clear communication channels between separate units that deal with aspects of cybersecurity.
1. Establish and maintain an organization-wide cybersecurity policy that's informed by standards.
2. Define roles and responsibilities for all personnel involved in cybersecurity.
3. Ensure your CISO/vCISO has a clear line of communication to leadership and the board as it relates to threats.
What areas of Cybersecurity Leadership would the CEO be concerned with?
Security program initiatives, governance, and culture
Security tools, risk assessment, and governance
Risk assessment, culture, and security leadership
Risk assessment, governance and culture
As it relates to a CEO's role in Risk Assessment and Management, the CEO should make sure a risk assessment is conducted in collaboration with your (a) .
Additional concerns for the CEO relative to Risk Assessment and Management are: (select all that apply)
Determine budget needs from assessment and present to board.
Analyze and present results of assessment to key stakeholders and the board.
Plan to oversee steps to increase cyber preparedness and monitor progress.
Assure security dashboard is up-to-date and relevant to current security status.
Who is responsible to establish recurring cybersecurity training for all staff?
Board of Directors
Security Management
CEO
CISO/vCISO
Who is responsible to institute an annual review of cybersecurity policies?
Board of Directors
CEO
CTO
CISO/vCISO
Who should ask the following question about potential cybersecurity threats: What type of critical information could be lost (e.g., trade secrets, customer data, research, PII)?
Board of Directors
CEO
CTO
CISO/vCISO
Which role is usually viewed as having a little less (direct/personal) ownership of the security program?
Board of Directors
CEO
CTO
CISO/vCISO
What is the main two jobs of a vCISO?
lead and direct
inform and dictate
listen and do
consult and implement
True or False: It is not that important for a vCISO to learn the "language" of the board, CEO and other executives because the "language" is pretty universal regardless of the organization.
True
False
The responsibilities of Technical Risk Management tends to fall on the vCISO because either they are doing the work themselves or telling others what they need to do.
True
False
Why is it important to have Information Security Committees?
The purpose of an Information Security Committee Charter is to design, implement, and manage an effective information security program.
True
False
Information Security Committees typically include a wide arrangement of IT employees.
True
False
It is important that all decisions are made by majority rules.
True
False
