WorksheetsM5C2
Total questions: 10
Worksheet time: 5mins
Name
Class
Date
1.
The Primary objective of implementing Information security management is to:
a)
Ensure reasonable security practices
b)
Comply with internal audit requirements
c)
Adopt globally recognized standards
d)
Protect information assets
2.
Which of the following is primary function of information security policies?
a)
Align information security practices with strategy
b)
Communicate intent of management to stakeholders
c)
Perform risk assessment of IT operations and assets
d)
Ensure compliance with requirements of standards
3.
Information security policies are set of various policies addressing different information systems areas based on the IT infrastructure of organization. Which of the following policy is most common in all organizations?
a)
Acceptable use policy
b)
BYOD (Bring Your Own Device) policy
c)
Data encryption policy
d)
Biometric security policy
4.
Protecting integrity of data primarily focuses on:
a)
Intentional leakage of data
b)
Accidental loss of data
c)
Accuracy and completeness
d)
Data backup procedures
5.
Which of the following is primary reason for periodic review of security policy?
a)
Compliance requirements
b)
Changes on board of directors’
c)
Changes in environment
d)
Joining of new employees
6.
Which is best evidence indicting support and commitment of senior management for information security initiatives?
a)
Directive for adopting global security standard
b)
Higher percentage of budget for security projects
c)
Assigning responsibilities for security to IT head
d)
Information security is on monthly meeting agenda
7.
Which of the following is a concern for compliance with information security policy?
a)
Decrease in low risk findings in audit report
b)
High number of approved and open policy exceptions
c)
Security policy is reviewed once in two years
d)
Security policy is signed by Chief Information Officer
8.
Which of the following is Primary purpose of Information classification?
a)
Comply with regulatory requirement
b)
Assign owner to information asset
c)
Provide appropriate level of protection
d)
Reduce costs of data protection
9.
Classification of information is primarily based on:
a)
Where the information is stored?
b)
Who has access to information?
c)
What will happen if information is not available?
d)
Why attachments to mail are encrypted?
10.
Which of the following best helps in classifying the information within organizations?
a)
Using minimum classes in classification schema
b)
Conducting training on classification schema
c)
Labeling all information based on classification schema
d)
Determining storage based on classification schema
100 %
