Font size
WorksheetsIS116-CHAPTER5 LONG QUIZ
Total questions: 21
Worksheet time: 21mins
What is the primary driver for the constant threat of security breaches?
Lack of security software on the market
Cyber threats advancing faster than existing frameworks
Employees refusing to follow security protocols
The high cost of implementing security measures
The Information Security Management Life Cycle (ISML) is important because it:
Is a one-time project that secures an organization permanently.
Replaces the need for a dedicated IT security team.
Moves security from a one-time project to a continuous business function.
Focuses solely on recovering from incidents after they happen.
Which of the following best describes a strategic goal in information security?
Deploy a new firewall by the end of the quarter.
Implement a governance framework to minimize organizational security risk.
Require all employees to change their passwords every 90 days.
Install encryption software on all company laptops.
A tactical action in information security is:
Aligning security goals with business objectives.
Conducting employee security training this quarter.
Developing a long-term vision for data protection.
Deciding to adopt the COBIT framework.
The COBIT framework is primarily focused on:
Providing a detailed code of practice for information security controls.
Bridging the gap between business risks and technical controls.
Offering a framework solely for responding to cyber-incidents.
Certifying the physical security of data centers.
Which framework is described as an "internationally recognized standard for establishing and maintaining an Information Security Management System (ISMS)"?
NIST Cybersecurity Framework
COBIT
ISO/IEC 27002
ITIL
The NIST Cybersecurity Framework's core functions include:
Identify, Protect, Detect, Respond, Recover
Plan, Do, Check, Act
Confidentiality, Integrity, Availability
Strategize, Implement, Monitor, Improve
A key role of a Technology Manager in governance is to:
Solely focus on writing code for security applications.
Translate high-level framework guidelines into actionable technical policies.
Take full and sole responsibility for all security breaches.
prevent the business leadership from being involved in security decisions.
Integrating security early and throughout the system development lifecycle is a philosophy known as:
Waterfall Development
"Shifting Left" or DevSecOps
Agile Scrambling
Total Quality Management
What is the relationship between strategy and the ISML?
Strategy is a separate concept and has no relation to the ISML.
The strategy sets the direction for the entire lifecycle.
Tactics define the strategy, which then defines the ISML.
The ISML is only concerned with tactical, day-to-day operations.
The most appropriate framework for an information security office is often:
NIST, due to its focus on critical infrastructure.
ISO/IEC 27002, due to its detailed control sections.
COBIT, due to its comprehensive approach to IT governance and business alignment.
A custom framework developed in-house.
Which function is NOT part of the implied core components of the Information Security Management Life Cycle?
Implement security controls
Ignore minor security threats
Identify assets and risks
Monitor security effectiveness
Confidentiality, Integrity, and Availability in Information Security refers to:
(a)
What is a primary benefit of integrating risk management into the ISML?
It allows an organization to completely eliminate all risks.
It helps prioritize security actions based on identified vulnerabilities.
It is a one-time activity that doesn't need repetition.
It removes the need for security frameworks.
The tactic of "deploying encryption for all data in transit" directly supports the strategic goal of:
Reducing IT staffing costs.
Improving network speed.
Implementing controls to protect information confidentiality.
Developing new software products.
Which framework provides a "prioritized, flexible, and risk-based approach" for organizations?
COBIT
ISO/IEC 27002
NIST Cybersecurity Framework
ITIL
From a manager's perspective, what is a key advantage of using a recognized framework like COBIT or ISO 27002?
It guarantees that no security breaches will occur.
It provides a structured way to demonstrate compliance and align IT with business goals.
It automatically implements all necessary technical controls.
It removes the need for employee security training.
The concept of "Integrating security early in the development process" in DevSecOps means:
(a)
Why is information considered one of the most valuable assets of an organization?
The role of a Technology Manager as an "Alignment Champion" involves:
Ensuring the IT department's goals are separate from the business's goals.
Demonstrating how IT security supports and enables core business objectives.
Championing for a lower IT budget.
Aligning only with other technology vendors.
Organizations must adapt a (a) approach to information security:
