1
IFT 483 CHAPTER 1-2 QUESTIONS AND ANSWERS REVISION GUIDE: INFORMATION SECURITY
POLICY MANAGEMENT, GOVERNANCE, AND RISK ALIGNMENT
Arizona State University
Course Revision Guide: Chapter 1 – securing information through structured policy management,
governance, and a systematic life cycle approach
Multiple-Choice Questions
1. Which term refers to a human-caused or natural event that could impact an information system?
A. Vulnerability
B. Risk
C. Threat
D. Control
Threat
A threat is defined as any human-caused or natural event with potential to harm the system.
2. What is the primary purpose of governance within an organization?
A. To develop new technology
B. To ensure compliance with established rules
C. To increase employee salaries
D. To reduce product costs
To ensure compliance with established rules
Governance ensures adherence to policies, processes, standards, and guidelines to meet business
requirements.
3. Which domain of the ISS management life cycle focuses on schedules, deliverables, and building security
controls?
A. Align, Plan, and Organize
B. Deliver, Service, and Support
C. Monitor, Evaluate, and Assess
D. Build, Acquire, and Implement
2
Build, Acquire, and Implement
This phase addresses building controls based on requirements from the planning phase.
4. Which IA tenet ensures that information has not been improperly changed?
A. Confidentiality
B. Availability
C. Integrity
D. Authentication
Integrity
Integrity ensures information changes only with owner approval or approved processes.
5. What type of control function does quality assurance (QA) primarily perform?
A. Detective control
B. Corrective control
C. Preventive control
D. Reactive control
Preventive control
QA acts as a preventive control by stopping mistakes before they occur.
6
everything is okay but rewrite and before the explanation, then begin with the word "Justification:" in bold,
followed by the justification sentence"
Okay, let's start by looking at the user's request. They want everything to be rewritten so that before the
explanation, the word "Justification:" in bold is included, followed by the justification sentence. The current
response has the answer and then the explanation. I need to adjust the format.
First, I need to go through each question and make sure the structure is consistent. Each should have the
question, answer in bold, then "Justification:" followed by the reason. Let me check the example provided.
The user mentioned that the justification should start right after the answer. In the current response, the
explanation is on a new line. Should I keep the answer and justification on separate lines or combine them?
Wait, the user's example shows the justification on a new line. So after the bold answer, a new line with
"Justification:" and then the sentence. Also, ensure that the justification references the correct terms from
3
the chapter. Let me verify each justification against the source material. For instance, in question 1, threat
is defined correctly. Need to make sure all justifications are accurate and derived only from the chapter.
Also, the user might be an instructor creating exams or study materials. They want a clear format that
separates the answer from the reasoning, making it easier for students to understand. The mention of
"before the explanation" means the justification comes after the answer but before any additional notes.
Making sure the formatting is consistent across all questions.
Double-checking each justification: Question 2's justification talks about governance ensuring compliance,
which matches the chapter's definition. Question 3's justification correctly identifies the Build, Acquire, and
Implement phase. All justifications should be concise and directly from the text.
Potential deeper needs: The user might need these for a textbook or an online learning platform where
justifications help in self-assessment. They might want to avoid legal issues by ensuring all content is
sourced from the provided chapter. Also, maintaining academic integrity by not using external sources.
Finally, ensure that every question follows the same structure without deviation. Check for any missed
formatting like bold text for "Justification:" and correct line breaks. Also, confirm that all justifications are
single sentences as per the earlier instruction.
Multiple-Choice Questions
1. Which term refers to a human-caused or natural event that could impact an information system?
A. Vulnerability
B. Risk
C. Threat
D. Control
Threat
Justification: A threat is defined as any human-caused or natural event with potential to harm the system.
2. What is the primary purpose of governance within an organization?
A. To develop new technology
B. To ensure compliance with established rules
C. To increase employee salaries
D. To reduce product costs
4
To ensure compliance with established rules
Justification: Governance ensures adherence to policies, processes, standards, and guidelines to meet
business requirements.
3. Which domain of the ISS management life cycle focuses on schedules, deliverables, and building security
controls?
A. Align, Plan, and Organize
B. Deliver, Service, and Support
C. Monitor, Evaluate, and Assess
D. Build, Acquire, and Implement
Build, Acquire, and Implement
Justification: This phase addresses building controls based on requirements from the planning phase.
4. Which IA tenet ensures that information has not been improperly changed?
A. Confidentiality
B. Availability
C. Integrity
D. Authentication
Integrity
Justification: Integrity ensures information changes only with owner approval or approved processes.
5. What type of control function does quality assurance (QA) primarily perform?
A. Detective control
B. Corrective control
C. Preventive control
D. Reactive control
Preventive control
Justification: QA acts as a preventive control by stopping mistakes before they occur.
6. What is the main difference between a policy and a procedure?
A. A policy is optional, a procedure is mandatory.
B. A policy states requirements, a procedure details steps.
C. A policy is technical, a procedure is managerial.
D. A policy is external, a procedure is internal.
A policy states requirements, a procedure details steps.
5
Justification: Policies state organizational requirements, while procedures describe step-by-step
instructions to implement processes.
7. Which concept represents the likelihood and impact of a threat exploiting a vulnerability?
A. Threat
B. Vulnerability
C. Risk
D. Control
Risk
Justification: Risk is defined as the combination of an event's probability and its resulting impact.
8. What is a primary goal of the confidentiality tenet?
A. Ensuring system uptime
B. Preventing data tampering
C. Limiting access to authorized individuals
D. Verifying user identity
Limiting access to authorized individuals
Justification: Confidentiality ensures only authorized individuals can access specific information.
9. Which document establishes high-level rules and tone for security across an enterprise?
A. Procedure
B. Standard
C. Guideline
D. Principles
Principles
Justification: Principles communicate common rules and core values that guide policy creation.
10. During which life cycle phase are lessons learned collected and operations improved?
A. Align, Plan, and Organize
B. Build, Acquire, and Implement
C. Deliver, Service, and Support
D. Monitor, Evaluate, and Assess
Deliver, Service, and Support
Justification: This phase involves tuning the environment and applying lessons learned to improve
operations.
6
11. What is the key purpose of a Service Level Agreement (SLA)?
A. To define employee conduct
B. To state a commitment to a specific service level
C. To outline security principles
D. To list software standards
To state a commitment to a specific service level
Justification: An SLA is a stated commitment to provide a defined level of service, such as availability or
response time.
12. Which term describes data stored on a backup tape?
A. Data in transit
B. Data at rest
C. Data in process
D. Data in use
Data at rest
Justification: Data at rest refers to information in storage, such as on a backup tape.
13. What makes policy enforcement challenging?
A. Clearly defined roles
B. Well-written policies
C. Failure to report infractions
D. Strong management involvement
Failure to report infractions
Justification: A key enforcement challenge is when policy violations are not reported within the
organization.
14. Which activity is part of the Monitor, Evaluate, and Assess domain?
A. Writing new procedures
B. Acquiring new equipment
C. Conducting internal audits
D. Defining project management
Conducting internal audits
Justification: This phase includes independent assessments like internal and external audits.
7
15. The "need to know" principle directly supports which information assurance tenet?
A. Availability
B. Nonrepudiation
C. Integrity
D. Confidentiality
Confidentiality
Justification: The need to know principle restricts access to necessary information, upholding
confidentiality.
16. What does nonrepudiation provide assurance of?
A. System reliability
B. Data accuracy
C. Inability to deny an action
D. User authentication
Inability to deny an action
Justification: Nonrepudiation ensures an individual cannot deny having performed a digital transaction.
17. Which document is considered external to an organization's policy framework?
A. Policy
B. Procedure
C. Standard
D. Guideline
Standard
Justification: Standards are often external industry norms that influence internal policy creation.
18. What is a foundational reason for enforcing security policies?
A. Increasing system complexity
B. Protecting systems from the insider threat
C. Reducing employee training
D. Eliminating all vulnerabilities
Protecting systems from the insider threat
Justification: Policies help monitor authorized user activity, which is a significant insider threat.
19. Which phase involves reviewing contracts and holding suppliers accountable?
A. Build, Acquire, and Implement
8
B. Deliver, Service, and Support
C. Align, Plan, and Organize
D. Monitor, Evaluate, and Assess
Align, Plan, and Organize
Justification: This domain involves planning how to hold suppliers accountable for their deliveries and
SLAs.
20. What is the role of a guideline within a policy framework?
A. It is a mandatory technical specification.
B. It is an optional parameter for action.
C. It is a step-by-step instruction manual.
D. It is an external regulatory mandate.
It is an optional parameter for action.
Justification: A guideline suggests a course of action but is not mandatory like a policy or procedure.
21. What does the availability tenet ensure?
A. Data is encrypted.
B. Information is accessible to authorized users.
C. Users are who they claim to be.
D. Data remains unaltered.
Information is accessible to authorized users.
Justification: Availability ensures information and systems are accessible when needed by authorized
parties.
22. Business Process Reengineering (BPR) requires updating policies to avoid what?
A. Increased costs
B. A window of opportunity for error
C. Employee satisfaction
D. Faster process completion
A window of opportunity for error
Justification: Failing to update policies during BPR leaves a gap where new vulnerabilities can be
introduced.
23. What is a key outcome of effective governance?
A. Reduced need for management
9
B. Assurance that rules are followed
C. Elimination of all risks
D. Automatic policy creation
Assurance that rules are followed
Justification: Good governance provides confidence that policies and procedures are being adhered to.
24. Which concept is an extension of identification and authentication services?
A. Confidentiality
B. Integrity
C. Nonrepudiation
D. Availability
Nonrepudiation
Justification: Nonrepudiation is described as an end-to-end service extending authentication to prevent
denial of actions.
25. What is a primary challenge in winning policy acceptance?
A. Lack of technological support
B. Organizational support at all levels
C. Excessively simple language
D. Too few policies
Organizational support at all levels
Justification: Cohesive support from all organizational levels is essential for policy acceptance and
enforcement.
26. In the ISS life cycle, what follows the Build, Acquire, and Implement phase?
A. Align, Plan, and Organize
B. Monitor, Evaluate, and Assess
C. Deliver, Service, and Support
D. Retire, Dispose, and Replace
Deliver, Service, and Support
Justification: After implementation, the cycle moves to delivering, servicing, and supporting the systems.
27. Which term best describes a weakness in a system that can be exploited?
A. Threat
B. Risk
10
C. Vulnerability
D. Impact
Vulnerability
Justification: A vulnerability is a specific weakness in a system that a threat could potentially exploit.
28. What does the quality control (QC) function primarily involve?
A. Preventing errors before they happen
B. Detecting errors after they occur
C. Writing new policies
D. Approving budget requests
Detecting errors after they occur
Justification: QC is a detective control that reviews past actions to improve future quality.
29. When is an Information Systems Security policy initially needed?
A. After a major breach occurs
B. When new technology is introduced
C. During annual budget planning
D. When an employee requests one
When new technology is introduced
Justification: Policies should be in place before new technology is implemented to govern its secure use.
30. What is the purpose of a policy definitions document?
A. To list procedural steps
B. To provide optional suggestions
C. To define terms used in policies
D. To summarize audit findings
To define terms used in policies
Justification: This document clarifies terminology to ensure consistent interpretation of policies.
31. What is a significant danger of implementing the wrong security policies?
A. Increased employee morale
B. Guaranteeing information assurance tenets
C. Conflicting policies and delayed investigations
D. Reduced need for governance
11
Conflicting policies and delayed investigations
Justification: Wrong or conflicting policies can create confusion and hinder incident response.
32. Which domain touches all other domains in the COBIT-based life cycle?
A. Build, Acquire, and Implement
B. Deliver, Service, and Support
C. Monitor, Evaluate, and Assess
D. Align, Plan, and Organize
Align, Plan, and Organize
Justification: This initial domain determines how the project is managed, affecting all subsequent phases.
33. Encryption can help ensure both confidentiality and what other tenet?
A. Availability
B. Integrity
C. Authentication
D. Nonrepudiation
Integrity
Justification: Encryption protects data from being viewed or changed by unauthorized users, supporting
integrity.
34. What is the focus of Information Assurance (IA) compared to Information Systems Security (ISS)?
A. ISS focuses on process, IA focuses on format.
B. IA focuses on protecting information during process and use.
C. ISS is a subset of physical security only.
D. IA only concerns authentication.
IA focuses on protecting information during process and use.
Justification: IA imposes controls to protect data while it is being processed, stored, or transmitted.
35. What does change management critically aim to avoid during system upgrades?
A. Increasing functionality
B. Disrupting current services
C. Reducing costs
D. Writing new procedures
Disrupting current services
Justification: Change management times changes to avoid service disruption when adding new services.
12
36. Which assessment is performed by an outside firm hired by the company?
A. Self-Assessment
B. Internal Audit
C. Regulator Audit
D. External Audit
External Audit
Justification: An external audit is conducted by an outside firm to validate internal work or financial
statements.
37. What does the concept of "entitlement" refer to?
A. The right to govern
B. Fine-grained granting of access via an application
C. A type of vulnerability
D. A mandatory standard
Fine-grained granting of access via an application
Justification: Entitlement allows restrictive access control, such as limiting transaction amounts within an
application.
38. Running a business without policies would most likely lead to what?
A. Consistent quality
B. Predictable operations
C. Lack of regulatory compliance
D. Strong customer satisfaction
Lack of regulatory compliance
Justification: Without policies, individuals may decide when to follow laws, leading to non-compliance.
39. What is a primary driver for creating security policies?
A. Employee preferences
B. Laws and regulations
C. Vendor recommendations
D. Technology trends
Laws and regulations
Justification: Legal and regulatory requirements are key factors driving organizational security policy
needs.
13
40. Which pillar of the IA model is generally not considered a core ISS tenet?
A. Confidentiality
B. Integrity
C. Authentication
D. Availability
Authentication
Justification: Authentication is listed as a tenet generally accepted within IA but not specifically within ISS.
41. What is the purpose of continuous improvement in the context of ISS?
A. To eliminate all audits
B. To find better ways and apply lessons learned
C. To reduce the need for policies
D. To automate governance
To find better ways and apply lessons learned
Justification: Continuous improvement captures employee suggestions and lessons to enhance systems
and processes.
42. What is the relationship between a threat and a vulnerability?
A. They are the same concept.
B. A threat exploits a vulnerability.
C. A vulnerability causes a threat.
D. They are unrelated.
A threat exploits a vulnerability.
Justification: A threat is an event that can exploit a specific system weakness, which is a vulnerability.
43. Why are principles important in a policy framework?
A. They provide step-by-step instructions.
B. They communicate high-level rules and tone.
C. They are optional guidelines.
D. They detail technical standards.
They communicate high-level rules and tone.
Justification: Principles express core organizational values and set the authority for policy enforcement.
44. What is a key activity in the Deliver, Service, and Support domain?
A. Writing initial policies
14
B. Performing penetration testing
C. Acquiring new hardware
D. Defining strategic direction
Performing penetration testing
Justification: This phase includes activities like penetration testing to make critical security adjustments.
45. What does the Federal ESIGN Act define?
A. Information security standards
B. The concept of nonrepudiation
C. Electronic signatures
D. Service level agreements
Electronic signatures
Justification: The ESIGN Act provides the legal definition for electronic signatures used in transactions.
46. What is a major challenge to the availability of information systems?
A. Strong passwords
B. Encryption at rest
C. Denial of Service (DoS) attacks
D. Change management procedures
Denial of Service (DoS) attacks
Justification: DoS attacks flood servers to overwhelm them and make services unavailable.
47. What does a well-constructed policy dictionary help achieve?
A. Shorter policy documents
B. Clear and concise policy language
C. Fewer required audits
D. Elimination of guidelines
Clear and concise policy language
Justification: Defining terms ensures words in policies are rich in meaning and interpreted consistently.
48. In governance, what function does a committee perform if it reviews actions after the fact?
A. Quality Assurance
B. Quality Control
C. Risk Management
D. Strategic Planning
15
Quality Control
Justification: A QC function involves reviewing past actions to learn from mistakes and improve.
49. What is a critical success factor for implementing policies?
A. Complex technical language
B. Employee acceptance and management enforcement
C. Avoiding any changes
D. Focusing only on external threats
Employee acceptance and management enforcement
Justification: Policies are ineffective without employee adherence and management's commitment to
enforce them.
50. What is the ultimate goal of the ISS management life cycle?
A. To eliminate all staff
B. To deliver value and meet organizational goals
C. To purchase the latest technology
D. To write the most policies
To deliver value and meet organizational goals
Justification: The life cycle aims to deliver stakeholder value and achieve business objectives through
managed processes.
Fill In Blank Spaces
51. The __________ is a framework for managing and governing IT processes, with a core of four domains.
COBIT framework
Justification: COBIT is an international best practices framework for IT governance and management.
52. The five pillars of the IA model are confidentiality, integrity, availability, authentication, and __________.
nonrepudiation
Justification: Nonrepudiation is the fifth tenet of the IA model, ensuring an individual cannot deny an
action.
16
53. A(n) __________ is a stated commitment to provide a specific level of service, such as system availability.
Service Level Agreement (SLA)
Justification: An SLA formally defines the service level a provider commits to deliver.
54. The __________ phase of BPR develops the future process and updates policies.
fourth phase
Justification: Phase 4 of Business Process Reengineering involves developing the new process and
updating documentation.
55. __________ is the act of protecting information and the systems that store and process it.
Information Systems Security (ISS)
Justification: ISS involves protecting information and its systems from unauthorized access, use, or
destruction.
56. A __________ is a weakness in a system that can be exploited by a threat.
vulnerability
Justification: A vulnerability is a specific flaw or weakness that can be targeted.
57. __________ ensures that information is accessible to authorized users and devices when needed.
Availability
Justification: The availability tenet focuses on reliable access to information and systems.
58. The __________ domain of the ISS life cycle answers "What do you want to do?" and "How do you get
there?"
Align, Plan, and Organize
Justification: This initial domain establishes high-level requirements and plans.
59. A written statement describing the steps to implement a process is called a __________.
procedure
Justification: Procedures provide detailed, step-by-step instructions to perform tasks.
60. __________ is both a concept and a set of actions to ensure compliance with organizational rules.
Governance
Justification: Governance involves processes and structures to enforce adherence to policies and
standards.
61. The biggest hindrance to policy implementation is the __________ factor.
human
Justification: Employee behavior and acceptance are the primary challenges to implementing policies.
17
62. A policy __________ document defines the terms used to ensure clear interpretation.
definitions
Justification: This document provides precise meanings for terminology used within policies.
63. Data stored on a backup tape is an example of data __________.
at rest
Justification: Data at rest refers to information in a stored, non-transient state.
64. The __________ tenet verifies the identity of a user or device attempting to access a system.
authentication
Justification: Authentication confirms the identity of an entity before granting access.
65. Quality __________ is a preventive control that stops mistakes before they happen.
assurance (QA)
Justification: QA functions as a preventive control by reviewing and approving actions upfront.
66. The __________ threat refers to the risk posed by users with authorized access to systems.
insider
Justification: The insider threat involves privileged users who could misuse their authorized access.
67. __________ is the probability of an event occurring and the magnitude of its impact.
Risk
Justification: Risk combines the likelihood of a threat event with its potential consequences.
68. In the policy framework, a __________ is an optional parameter suggesting a course of action.
guideline
Justification: Guidelines offer suggested, non-mandatory approaches within the policy structure.
69. The __________ domain involves tuning the environment and applying lessons learned.
Deliver, Service, and Support
Justification: This operational phase focuses on support and continuous improvement.
70. __________ management is critical during upgrades to avoid disrupting current services.
Change
Justification: Change management coordinates system modifications to maintain service continuity.
71. The need-to-know principle is primarily used to uphold information __________.
confidentiality
Justification: Restricting access based on necessity is a core method for maintaining confidentiality.
18
72. An audit performed by a government agency to assess legal compliance is a __________ audit.
regulator
Justification: Regulator audits are conducted by government entities to evaluate compliance with laws.
73. The __________ phase includes independent assessments like internal and external audits.
Monitor, Evaluate, and Assess
Justification: This domain focuses on oversight, evaluation, and assessment of controls.
74. A(n) __________ is an established industry norm that influences policy creation.
standard
Justification: Standards are external benchmarks that shape organizational policies and controls.
75. __________ improvement involves capturing employee suggestions to find better methods.
Continuous
Justification: Continuous improvement is an ongoing effort to enhance processes based on feedback.
76. The __________ tenet ensures that data cannot be否认 as originating from a specific individual.
nonrepudiation
Justification: Nonrepudiation prevents an entity from denying involvement in a digital transaction.
77. The primary focus of __________ is protecting information during processing, storage, and transmission.
Information Assurance (IA)
Justification: IA imposes controls to protect information throughout its entire lifecycle and usage.
78. A __________ grants access rights to specific systems or data based on job requirements.
entitlement
Justification: Entitlement refers to the specific access permissions granted to a user or role.
79. __________ are high-level documents that express the core values and risk appetite of an organization.
Principles
Justification: Principles establish the fundamental rules and tone for all subsequent policies.
80. The __________ domain is where security controls are actually built and policies are written.
Build, Acquire, and Implement
Justification: This phase translates requirements into tangible controls, policies, and procedures.
81. Failure to update policies after Business Process __________ leaves a window for error.
Reengineering (BPR)
Justification: Outdated policies following process changes can introduce security gaps.
19
82. A __________ assessment is typically in the form of quality assurance and quality control activities.
self-assessment
Justification: Organizations conduct self-assessments internally to evaluate their own controls.
83. __________ is a legal concept upheld by evidence like digital signatures and strong authentication.
Nonrepudiation
Justification: Nonrepudiation relies on collected evidence to prove an individual's actions.
84. The __________ document states how the organization is to perform business functions.
policy
Justification: A policy document mandates how business functions and transactions should be conducted.
85. Employee __________ is essential for policy buy-in and is motivated by rewards or discipline.
acceptance
Justification: Gaining employee commitment is crucial for successful policy implementation.
86. Data traveling across a network is referred to as data __________.
in transit
Justification: Data in transit is information actively moving from one location to another.
87. A policy must have clear __________ and responsibilities to be enforceable.
roles
Justification: Enforceable policies explicitly define who is accountable for specific actions.
88. The __________ function reviews past actions to improve quality over time.
quality control (QC)
Justification: QC is a detective control that analyzes outcomes to enhance future performance.
89. __________ testing, such as penetration tests, is performed to adjust perimeter defenses.
Security
Justification: Security testing identifies vulnerabilities to inform adjustments to protective controls.
90. Without cohesive organizational support, policy __________ and enforcement will fail.
acceptance
Justification: Successful policy adoption requires commitment from all levels of the organization.
True/False Questions
20
91. Information Systems Security (ISS) and Information Assurance (IA) are interchangeable terms.
False
Justification: ISS focuses on protecting information regardless of form, while IA focuses on protection
during process and use.
92. A procedure describes the steps required to implement a process.
True
Justification: A procedure is a written statement providing step-by-step instructions for a task.
93. Standards are always internal documents created by the organization.
False
Justification: Standards are often external industry norms that influence internal policy creation.
94. The Build, Acquire, and Implement domain is the final phase of the ISS management life cycle.
False
Justification: The final phase is Monitor, Evaluate, and Assess; Build is an intermediate phase.
95. Nonrepudiation is generally accepted as a tenet of both ISS and IA.
False
Justification: Nonrepudiation is listed as a tenet generally associated with IA, not specifically with ISS.
96. A threat is the likelihood of an event occurring and its impact.
False
Justification: A threat is the event itself; risk is the combination of likelihood and impact.
97. Governance ensures accountability and monitors activity within an organization.
True
Justification: Governance involves oversight processes to ensure rules are followed and activities are
recorded.
98. A guideline is a mandatory document within the policy framework.
False
Justification: A guideline is an optional document that suggests parameters for action.
99. The principle of "need to know" supports the integrity tenet.
False
Justification: The "need to know" principle supports confidentiality by restricting data access.
21
100. Quality Assurance (QA) acts as a detective control.
False
Justification: QA is a preventive control; Quality Control (QC) is the detective function.
101. All employees should be granted administrator privileges to ensure operational efficiency.
False
Justification: Granting universal administrator privileges violates the principle of least privilege and
increases risk.
102. The Align, Plan, and Organize domain touches all other domains in the life cycle.
True
Justification: This initial planning domain sets the management approach that influences all subsequent
phases.
103. Authentication is only concerned with verifying the identity of human users.
False
Justification: Authentication also applies to verifying the identity of devices, services, and automated
processes.
104. The main goal of a Denial of Service attack is to steal confidential information.
False
Justification: The goal of a DoS attack is to crash or overwhelm a system to make it unavailable, not to
steal data.
105. Encryption can only protect the confidentiality of data, not its integrity.
False
Justification: Encryption can protect both confidentiality and integrity by preventing unauthorized viewing
or alteration.
106. A policy definitions document is unimportant and often overlooked.
False
Justification: This document is critically important for ensuring clear and consistent interpretation of policy
terms.
107. Continuous improvement should only be triggered after a system crash or breach.
False
Justification: Continuous improvement should be an ongoing process, not solely a reactive one.
22
108. An internal audit is performed by an outside firm hired by the company.
False
Justification: An internal audit is conducted by the organization's own staff; an external audit uses an
outside firm.
109. The Deliver, Service, and Support domain involves defining strategic business direction.
False
Justification: Strategic direction is set in the Align, Plan, and Organize domain; Deliver is focused on
operations.
110. Implementing the wrong policies can be as dangerous as having no policies.
True
Justification: Incorrect policies can create conflicts, confusion, and introduce new risks or compliance
gaps.
111. A vulnerability is a human-caused event like a hacker attack.
False
Justification: A vulnerability is a system weakness; the hacker attack is the threat that exploits it.
112. Service Level Agreements (SLAs) are only relevant during the Build, Acquire, and Implement
phase.
False
Justification: SLAs are defined in Align, Plan, and Organize, used in Build, and managed in Deliver,
Service, and Support.
113. The purpose of governance is to develop new technology solutions.
False
Justification: The purpose of governance is to ensure compliance with rules, not to develop technology.
114. A standard is the same as a policy but uses different terminology.
False
Justification: Standards are external norms; policies are internal mandates that may be based on
standards.
115. Data at rest refers to information actively being processed by a computer's CPU.
False
Justification: Data at rest is in storage; data being processed is typically referred to as data in use.
23
116. The Monitor, Evaluate, and Assess domain ensures controls keep pace with technological
changes.
True
Justification: This oversight phase evaluates if controls and policies remain effective amidst change.
117. Business Process Reengineering (BPR) never affects security policies.
False
Justification: BPR can introduce new vulnerabilities, making a review and update of security policies
imperative.
118. A risk is always present whenever a threat or vulnerability exists.
True
Justification: The presence of a threat or vulnerability creates some level of risk, however small.
119. The biggest challenge to policy enforcement is technological complexity.
False
Justification: The biggest hindrance is the human factor, including acceptance and behavior.
120. Principles are detailed technical specifications for system configuration.
False
Justification: Principles are high-level statements of rules and values, not technical specifications.
121. Availability requirements are determined solely by the IT department.
False
Justification: Availability requirements are determined by the information owner based on business needs.
122. An external audit certifies annual financial statements.
True
Justification: External audits are often conducted to validate and certify financial statements.
123. A policy framework consists only of policies and procedures.
False
Justification: A full framework includes principles, policies, standards, procedures, guidelines, and
definitions.
124. Change management is unimportant for systems not facing the Internet.
False
Justification: Change management is critical for all systems to control vulnerabilities, regardless of
Internet exposure.
24
125. A guideline can eventually transition into a policy.
True
Justification: Once a guideline's approach is widely adopted, it can be formalized into a mandatory policy.
126. Information Assurance (IA) grew from Information Systems Security (ISS).
True
Justification: The text states that IA grew from the foundation of ISS.
127. All types of assessments provide equally independent opinions.
False
Justification: Independence is relative; external audits are considered more independent than self-
assessments.
128. The "insider threat" is the most significant threat to any information system.
True
Justification: The text identifies privileged users with authorized access as the most significant threat.
129. COBIT is only a life cycle model and not a governance framework.
False
Justification: COBIT is more than a life cycle; it is a framework for managing and governing IT processes.
130. Policies should be written after a new technology is fully deployed.
False
Justification: Policies should be created before new technology is implemented to govern its secure use.
Flashcards / Rapid Review Items
131. Q: What are the four domains of the COBIT-based ISS management life cycle?
A: Align, Plan, and Organize; Build, Acquire, and Implement; Deliver, Service, and Support; Monitor,
Evaluate, and Assess.
132. Q: Name the five pillars (tenets) of the Information Assurance model.
A: Confidentiality, Integrity, Availability, Authentication, Nonrepudiation.
133. Q: What type of control is Quality Assurance (QA)?
A: A preventive control.
25
134. Q: What document provides step-by-step instructions to perform a task?
A: A procedure.
135. Q: Define 'risk' in the context of ISS.
A: The likelihood or probability of an event and its impact.
136. Q: What is the primary goal of the confidentiality tenet?
A: To ensure only authorized individuals can access information.
137. Q: What is an SLA?
A: A Service Level Agreement, a stated commitment to a specific service level.
138. Q: What is the difference between a threat and a vulnerability?
A: A threat is an event; a vulnerability is a weakness the threat can exploit.
139. Q: Which governance function reviews actions after the fact?
A: Quality Control (QC).
140. Q: What is data called when it is moving across a network?
A: Data in transit.
141. Q: What principle restricts access to only necessary information?
A: The need-to-know principle.
142. Q: What is the purpose of a policy definitions document?
A: To define terms used in policies for clear interpretation.
143. Q: What does nonrepudiation prove?
A: That an individual cannot deny performing a specific digital action.
144. Q: Which life cycle phase involves collecting lessons learned?
A: The Deliver, Service, and Support phase.
145. Q: What is a standard?
A: An established industry norm or method that influences policies.
146. Q: What is the biggest hindrance to policy implementation?
A: The human factor (employee acceptance and behavior).
147. Q: What does BPR stand for?
A: Business Process Reengineering.
148. Q: What tenet does encryption help support besides confidentiality?
A: Integrity.
26
149. Q: What is the focus of Information Assurance (IA)?
A: Protecting information during process and use.
150. Q: What is an entitlement?
A: The fine-grained granting of access rights, often through an application.
151. Q: What does a guideline provide?
A: An optional parameter or suggestion for action.
152. Q: What is the main challenge to availability from attackers?
A: Denial of Service (DoS) attacks.
153. Q: Who typically approves a policy within an organization?
A: The most senior levels of management.
154. Q: What is the purpose of continuous improvement?
A: To find better ways of operating by capturing lessons and suggestions.
155. Q: What type of audit does a government agency perform?
A: A regulator audit.
156. Q: What is the "insider threat"?
A: The risk posed by users with authorized system access.
157. Q: What does change management coordinate?
A: System modifications to avoid service disruption.
158. Q: What are principles in a policy framework?
A: High-level documents expressing core organizational rules and values.
159. Q: What is assessed during the Monitor, Evaluate, and Assess domain?
A: Whether controls and policies keep pace with technology and environmental changes.
160. Q: What is necessary for policy enforcement?
A: Clearly defined roles, responsibilities, and reporting of infractions.
Application-Based Questions
161. A bank is creating a policy for its check-cashing process. Which life cycle domain should first
define the requirement to verify customer identification?
27
A: Align, Plan, and Organize
B: Build, Acquire, and Implement
C: Deliver, Service, and Support
D: Monitor, Evaluate, and Assess
Align, Plan, and Organize
Justification: Defining high-level business requirements and controls is the purpose of the Align, Plan, and
Organize domain.
162. An e-commerce company's website is overwhelmed by traffic, making it unavailable to customers.
Which IA tenet is most directly violated?
A: Confidentiality
B: Integrity
C: Availability
D: Nonrepudiation
Availability
Justification: The inability of authorized customers to access the website is a failure of the availability
tenet.
163. During a post-incident review, a company discovers an employee changed financial data without
approval. Which tenet was compromised?
A: Confidentiality
B: Integrity
C: Authentication
D: Availability
Integrity
Justification: Unauthorized modification of data violates the integrity tenet.
164. A policy states "All remote access must use multi-factor authentication." What type of document
would detail the steps to configure the authentication server?
A: Principle
B: Standard
C: Procedure
D: Guideline
Procedure
28
Justification: A procedure provides the technical, step-by-step instructions to implement a policy
requirement.
165. An audit finds that a server configuration standard from 2010 is still in use, but technology has
significantly changed. Which life cycle phase should address this gap?
A: Build, Acquire, and Implement
B: Deliver, Service, and Support
C: Align, Plan, and Organize
D: Monitor, Evaluate, and Assess
Monitor, Evaluate, and Assess
Justification: This oversight phase evaluates if controls and standards remain current with technology
changes.
166. A hospital introduces new patient monitoring equipment. When should associated security policies
be created?
A: After the first security incident occurs
B: Before the equipment is installed and used
C: During the annual budget process
D: Only if required by an external auditor
Before the equipment is installed and used
Justification: Security policies should govern new technology before its implementation to manage risk
from the start.
167. A company's governance committee reviews and approves every software change before it is
deployed. What function is this committee performing?
A: Quality Control
B: Quality Assurance
C: Risk Assessment
D: Change Implementation
Quality Assurance
Justification: Reviewing and approving an action before it happens is a preventive QA function.
168. An employee in payroll can access salary data but not employee medical records. This is an
example of which principle?
A: Least Privilege
29
B: Need to Know
C: Separation of Duties
D: Continuous Monitoring
Need to Know
Justification: Access is granted only to the specific information (salary data) necessary for the employee's
job function.
169. After a supplier's system was hacked, leading to a breach at Target, which domain's failure was
highlighted regarding SLAs and contracts?
A: Build, Acquire, and Implement
B: Deliver, Service, and Support
C: Monitor, Evaluate, and Assess
D: Align, Plan, and Organize
Align, Plan, and Organize
Justification: This domain includes ensuring contracts and SLAs properly define and hold suppliers
accountable for security obligations.
170. A company wants to ensure that a customer cannot deny making an online purchase. Which
technology or concept is most relevant?
A: Data Encryption
B: Firewall Configuration
C: Nonrepudiation
D: Vulnerability Scanning
Nonrepudiation
Justification: Nonrepudiation provides assurance that a party cannot deny involvement in a transaction,
such as a purchase.
171. During which phase would an organization likely perform a penetration test to adjust its firewall
rules?
A: Align, Plan, and Organize
B: Build, Acquire, and Implement
C: Deliver, Service, and Support
D: Monitor, Evaluate, and Assess
30
Deliver, Service, and Support
Justification: This operational phase includes activities like penetration testing to tune security controls.
172. An employee suggests a more secure method for handling customer data. What process should
capture this idea?
A: Business Process Reengineering
B: Change Management
C: Continuous Improvement
D: External Audit
Continuous Improvement
Justification: Continuous improvement involves capturing employee suggestions for finding better ways to
operate.
173. A policy states "Sensitive data must be encrypted." What supporting document would list the
approved encryption algorithms?
A: Procedure
B: Guideline
C: Standard
D: Principle
Standard
Justification: A standard would establish the specific technical criteria, like approved algorithms, to meet
the policy.
174. A review finds that different departments interpret the term "user" differently in the acceptable use
policy. What document needs improvement?
A: The Policy itself
B: The Procedure manual
C: The Policy definitions document
D: The Governance charter
The Policy definitions document
Justification: This document defines terms to ensure consistent interpretation across the organization.
175. What is the primary security risk if a company's change management process fails?
A: Increased software costs
B: Introduction of system vulnerabilities
31
C: Slower employee onboarding
D: Too many policies
Introduction of system vulnerabilities
Justification: Poorly managed changes can misconfigure systems, creating new security weaknesses.
176. A financial firm must follow PCI DSS standards. What type of document are these standards for the
firm's policy team?
A: An internal principle
B: An external standard
C: A mandatory procedure
D: An optional guideline
An external standard
Justification: PCI DSS is an industry-established standard that externally influences the firm's internal
policies.
177. After a hurricane, a company cannot access its primary data center. Which life cycle concept
should have planned for this?
A: Vulnerability assessment in Build phase
B: Availability requirements in Align phase
C: Nonrepudiation in Deliver phase
D: Change management in Monitor phase
Availability requirements in Align phase
Justification: The Align, Plan, and Organize domain should identify natural threats and plan for availability
via recovery sites.
178. An automated payroll process needs to access the employee database. What must be verified
before granting this access?
A: The process's integrity
B: The process's availability
C: The process's authentication
D: The process's confidentiality
The process's authentication
Justification: Non-human entities like automated processes require identity verification (authentication)
before being granted access.
32
179. A company policy is consistently ignored because it is confusing. What is the most likely root
cause?
A: Lack of employee training
B: Poorly written policy language
C: Absence of governance
D: Too much monitoring
Poorly written policy language
Justification: Vague or confusing policy language makes understanding and compliance difficult for
employees.
180. What is the first step in responding to a security incident not covered by existing policy?
A: Draft a new policy immediately
B: Perform an event analysis
C: Discipline involved employees
D: Notify external regulators
Perform an event analysis
Justification: The text states that after an unaddressed event occurs, an analysis takes place before
making recommendations.
181. A manager can approve expenses but only up to $5,000. This restriction is an example of what?
A: An entitlement
B: A standard
C: A guideline
D: A vulnerability
An entitlement
Justification: This is a fine-grained access control that restricts the type and amount of transaction a user
can perform.
182. Which committee would review quarterly reports on policy violations to identify trends?
A: A Quality Assurance committee
B: A Quality Control committee
C: A Strategic Planning committee
D: A Policy Development committee
A Quality Control committee
33
Justification: Reviewing past violations to identify trends and improve future performance is a detective
QC function.
183. Why must security policies be updated during Business Process Reengineering (BPR)?
A: To increase the number of policies
B: To ensure new process vulnerabilities are addressed
C: To satisfy auditor requests
D: To reduce employee workloads
To ensure new process vulnerabilities are addressed
Justification: BPR can introduce new equipment or workflows, potentially creating new security
weaknesses that policies must cover.
184. A company wants to prove who signed an electronic contract. What provides the strongest
evidence?
A: A username and password log
B: A digitally signed document with a timestamp
C: An email confirmation receipt
D: A printed copy of the contract
A digitally signed document with a timestamp
Justification: A proper digital signature, legally binding under the ESIGN Act, provides strong evidence for
nonrepudiation.
185. An organization updates its technology but not its security policies. What is the most likely
consequence?
A: Increased employee satisfaction
B: Creation of system weaknesses
C: Reduced governance costs
D: Automatic compliance
Creation of system weaknesses
Justification: Failure to update policies alongside technology can leave gaps where new systems are not
properly governed, creating weaknesses.
186. What is the primary reason for involving key departments like Human Resources in policy
enforcement?
A: To reduce IT workload
34
B: To give employees a license to disregard policies
C: To ensure consistent disciplinary action
D: To write technical procedures
To ensure consistent disciplinary action
Justification: Involvement of HR and Legal is necessary for enforcing consequences, making policies
enforceable.
187. During an assessment, you find a system not connected to the Internet has a configuration error.
How would you initially assess the risk?
A: The risk is high because vulnerabilities are present.
B: The risk is low due to reduced threat exposure.
C: The risk is eliminated because there is no threat.
D: The risk is unknown without testing.
The risk is low due to reduced threat exposure.
Justification: The text uses a non-Internet facing system example to show that reduced threat access
lowers the probability and impact, thus lowering risk.
188. A vendor consistently fails to meet its SLA for system uptime. In which phase should this be
formally addressed with the vendor?
A: Build, Acquire, and Implement
B: Deliver, Service, and Support
C: Align, Plan, and Organize
D: Monitor, Evaluate, and Assess
Deliver, Service, and Support
Justification: This phase involves day-to-day vendor management, comparing SLA performance, and
addressing issues.
189. What is the main purpose of creating a "policy awareness" program for employees?
A: To increase the number of policies
B: To ensure employees know policies exist and understand them
C: To replace the need for procedures
D: To satisfy regulatory checklists
To ensure employees know policies exist and understand them
35
Justification: Policy awareness is a listed challenge; employees cannot follow policies they are unaware of
or do not understand.
190. After a successful penetration test, the team recommends stricter access controls. Which domain
will oversee implementing this recommendation?
A: Align, Plan, and Organize
B: Build, Acquire, and Implement
C: Deliver, Service, and Support
D: Monitor, Evaluate, and Assess
Build, Acquire, and Implement
Justification: Implementing new or adjusted security controls based on recommendations occurs in the
Build phase.
191. A company operates in a highly regulated industry. Why would strong governance benefit them?
A: It allows them to ignore regulations.
B: It may reduce the level of external regulatory oversight.
C: It eliminates the need for internal audits.
D: It automatically generates compliance reports.
It may reduce the level of external regulatory oversight.
Justification: Regulators have more confidence in companies with strong governance, potentially leading
to less frequent or intense scrutiny.
192. An employee uses a weak password that is easily guessed. Which two IA tenets are most directly
threatened?
A: Confidentiality and Integrity
B: Availability and Nonrepudiation
C: Authentication and Confidentiality
D: Integrity and Availability
Authentication and Confidentiality
Justification: A weak password compromises authentication, which in turn can lead to unauthorized
access, breaching confidentiality.
193. What is the key difference between an internal standard and an external standard?
A: Internal standards are optional, external are mandatory.
B: Internal standards are tailored by the organization, external are set by industry or regulators.
36
C: Internal standards are longer documents.
D: There is no difference.
Internal standards are tailored by the organization, external are set by industry or regulators.
Justification: Organizations often adapt external standards to create their own internal versions that fit
their specific needs.
194. A policy states "Departments must classify their data." What type of supporting document would
explain how to classify data but not mandate a specific method?
A: A Standard
B: A Procedure
C: A Guideline
D: A Principle
A Guideline
Justification: A guideline would offer suggested methods or parameters for data classification without
being mandatory.
195. Why is independence important for an audit?
A: It guarantees that no mistakes will be found.
B: It provides a more unbiased and independent opinion.
C: It makes the audit process faster.
D: It is required by all internal policies.
It provides a more unbiased and independent opinion.
Justification: The further one is from the actual work, the more independent and unbiased the assessment
can be.
37
Chapter 2 Revision Questions and Answers: Strategic Business Alignment & Risk Governance in
Information Security Policy Development
Multiple-Choice Questions
1. What is the primary relationship between security policies and business objectives?
A. Policies define technology budgets for security tools.
B. Policies restrict business operations to ensure absolute safety.
C. Aligning policies with objectives makes them easier to understand and follow.
D. Business objectives are derived from the organization's security policy manual.
C. Aligning policies with objectives makes them easier to understand and follow.
Alignment ensures policies support business goals, increasing clarity and adherence.
2. Which element is NOT listed as a key competing driver that security policies must help balance?
A. Cost reduction
B. Employee satisfaction
C. Customer satisfaction
D. Regulatory compliance
B. Employee satisfaction
The chapter identifies cost, customer satisfaction, compliance, and measurement as key competing drivers.
3. A security breach is best defined as a confirmed event that compromises what?
A. Employee morale and company reputation
B. System performance and network speed
C. The confidentiality, integrity, or availability of information
D. Physical access to data centers and server rooms
C. The confidentiality, integrity, or availability of information
A breach directly impacts the core security tenets of information assets.
4. According to the cited study, what was a primary cause of data breaches?
A. Advanced persistent threat (APT) attacks
B. Employee negligence
C. Natural disasters
38
D. Hardware failures
B. Employee negligence
The Poneman Institute study attributed 39% of data breaches to negligence.
5. What is a fundamental concern when implementing a security policy?
A. The impact on the business's ability to serve the customer
B. Guaranteeing complete elimination of all business risks
C. Selecting the most expensive security controls available
D. Ensuring policies are longer than 50 pages for thoroughness
A. The impact on the business's ability to serve the customer
Policy implementation must consider operational impact, not just security.
6. Why must management take part in creating security policies?
A. To ensure policies are written in highly technical language.
B. To avoid later surprises about policy cost or customer impact.
C. To delegate all policy enforcement to the IT department.
D. To limit policy access to senior leadership only.
B. To avoid later surprises about policy cost or customer impact.
Management involvement ensures policies are practical and aligned with business realities.
7. What does "security policy compliance" specifically mean?
A. Installing the latest antivirus software on all systems.
B. Adhering to the rules set forth in security policies.
C. Passing an annual external audit from regulators.
D. Completing security awareness training upon hire.
B. Adhering to the rules set forth in security policies.
Compliance is the act of following the established policy directives.
8. The key to security policy is being able to measure compliance against what?
A. A set of security controls
B. Competitor security postures
C. Employee satisfaction surveys
D. Annual financial budgets
A. A set of security controls
Controls define how protection is implemented, providing a basis for measurement.
39
9. A well-written security policy must strike a balance between being what?
A. Vague and highly detailed
B. Clear, concise, and broadly applicable
C. Technically complex and user-friendly
D. Voluntary and mandatory
B. Clear, concise, and broadly applicable
Effective policies provide clear guidance without being overly restrictive or vague.
10. What can a simple measurement of compliance potentially be?
A. Always perfectly accurate
B. Less accurate or misleading
C. The only measurement needed
D. Replaced by employee testimonials
B. Less accurate or misleading
Simple checks may not reflect the true risk exposure, as illustrated by the firewall example.
11. Security controls are the means of enforcing policies to ensure what?
A. The confidentiality, integrity, and availability of information.
B. That all employees have the same security clearance level.
C. That security policies are changed weekly.
D. All software is developed in-house.
A. The confidentiality, integrity, and availability of information.
Controls operationalize policies to protect the core security attributes of information.
12. What is an advantage of treating security policies and controls separately?
A. Policies can be ignored if controls are strong.
B. Controls can be updated independently as technology evolves.
C. Employees only need to learn about controls, not policies.
D. It reduces the total number of documents to manage.
B. Controls can be updated independently as technology evolves.
Separation allows controls to adapt to new technologies while the underlying policy goal remains stable.
13. A locked door is an example of what type of security control?
A. Administrative control
B. Technical control
40
C. Corrective control
D. Physical control
D. Physical control
Physical controls are tangible devices or barriers that prevent or deter access.
14. Security awareness training is an example of what type of security control?
A. Technical control
B. Physical control
C. Administrative control
D. Corrective control
C. Administrative control
Administrative (procedural) controls rely on human action, such as training.
15. A firewall is primarily considered what type of security control?
A. Physical control
B. Administrative control
C. Technical control
D. Compensating control
C. Technical control
Technical controls use software or dedicated hardware to create logical restrictions.
16. A preventive control is designed to do what?
A. Stop an incident from occurring.
B. Detect an incident after it occurs.
C. Correct damage after an incident.
D. Investigate the cause of an incident.
A. Stop an incident from occurring.
Preventive controls aim to block unauthorized actions before they cause harm.
17. An automated control is characterized by what?
A. Requiring human decisions to prevent an incident.
B. Containing logic in software to decide what action to take.
C. Being less effective than manual controls.
D. Applying only to physical security mechanisms.
41
B. Containing logic in software to decide what action to take.
Automated controls use programmed logic, eliminating the need for real-time human intervention.
18. A detective control, like reviewing a credit card statement, does what?
A. Prevents unauthorized charges from being made.
B. Alerts the organization that an incident might have occurred.
C. Automatically refunds any fraudulent charges.
D. Encrypts transaction data during transmission.
B. Alerts the organization that an incident might have occurred.
Detective controls identify events after they happen, triggering investigation or correction.
19. A manual control is defined by what requirement?
A. It must be performed daily.
B. It requires human action.
C. It is always less expensive than automated controls.
D. It cannot have any automated components.
B. It requires human action.
If human judgment or action is needed, the control is classified as manual.
20. A corrective control, like data restoration from backups, aims to do what?
A. Prevent future system crashes.
B. Limit business impact by correcting a vulnerability.
C. Detect the precise time of a hard drive failure.
D. Punish the employee responsible for the loss.
B. Limit business impact by correcting a vulnerability.
Corrective controls restore normal operations and fix problems after an incident.
21. What does "tone at the top" refer to in a security context?
A. The volume of security alerts generated by monitoring systems.
B. Senior management's stated commitment to and enforcement of security policies.
C. The highest level of encryption used by the organization.
D. The security policy approval hierarchy within the company.
B. Senior management's stated commitment to and enforcement of security policies.
It signifies leadership's active role in prioritizing and modeling security.
42
22. What is the ultimate goal of a security awareness program?
A. To make employees memorize policy documents word-for-word.
B. To make employees aware of expected behaviors regarding security.
C. To replace all technical security controls with vigilant employees.
D. To test employees weekly on obscure security facts.
B. To make employees aware of expected behaviors regarding security.
Awareness programs communicate expectations to influence employee behavior.
23. Which principle is NOT listed for implementing a security awareness program?
A. Repetition
B. Secrecy
C. Onboarding
D. Relevance
B. Secrecy
Accepted principles include repetition, onboarding, support, relevance, and metrics.
24. A risk-aware culture is best described as what?
A. A culture that avoids all risks at any cost.
B. A culture with a shared understanding of the importance of managing risks.
C. A culture where only the security department manages risk.
D. A culture that views security policies as optional guidelines.
B. A culture with a shared understanding of the importance of managing risks.
It involves common values and knowledge about risk management across the organization.
25. Intellectual property (IP) is broadly defined as what?
A. Only patented inventions and copyrighted software code.
B. Any company information thought to provide a competitive advantage.
C. Physical assets like servers and buildings.
D. Publicly available marketing brochures.
B. Any company information thought to provide a competitive advantage.
IP encompasses a wide range of unique, valuable business information.
26. What should security policies define regarding intellectual property?
A. The market value of each piece of IP.
B. How to protect that information regardless of its format.
43
C. Which employees are allowed to create IP.
D. The process for selling IP to competitors.
B. How to protect that information regardless of its format.
Policies must address protection for IP in both electronic and physical forms.
27. What is the difference between labeling and classifying data?
A. Labeling is electronic, classifying is physical.
B. Labeling places a mark on the document; classification may secure it in a location.
C. Classification is for internal use only, labeling is for external documents.
D. There is no difference; the terms are interchangeable.
B. Labeling places a mark on the document; classification may secure it in a location.
A label is a visible marker, while classification involves systematic handling based on sensitivity.
28. A widely accepted practice to prevent IP loss includes what combination?
A. Delete old data, use simple passwords, limit manager reviews.
B. Label/classify IP, restrict access, filter communications, educate employees.
C. Hire more security guards, use fingerprint readers, block the Internet.
D. Centralize all data, use one vendor, avoid cloud storage.
B. Label/classify IP, restrict access, filter communications, educate employees.
This multi-layered approach is a comprehensive strategy for IP protection.
29. Digital assets are strictly defined as what?
A. All computer hardware owned by the organization.
B. Any digital content owned by the organization or for which it has usage rights.
C. Only data that contains personally identifiable information (PII).
D. Software applications currently in development.
B. Any digital content owned by the organization or for which it has usage rights.
This includes created, purchased, or properly licensed digital materials like text, graphics, and video.
30. What is a major challenge in protecting digital assets?
A. Creating an accurate and current inventory of where data resides.
B. Convincing employees to use digital instead of paper records.
C. Finding vendors who sell digital asset management tools.
D. Defining what the term "digital" means in a policy.
44
A. Creating an accurate and current inventory of where data resides.
You cannot protect what you cannot find; inventory is the foundational step.
31. What is a recommended technique before applying automated classification controls?
A. Run tools in log mode to assess impact without taking action.
B. Apply controls immediately to the most sensitive data first.
C. Disable all access and see who complains.
D. Classify all data at the highest level to be safe.
A. Run tools in log mode to assess impact without taking action.
Log mode allows rehearsal and business impact assessment before full enforcement.
32. Personally Identifiable Information (PII) is information that can do what?
A. Only identify a person when combined with a secret password.
B. Distinguish or trace an individual's identity alone or when combined.
C. Be found only in government databases.
D. Be legally sold without any consumer consent.
B. Distinguish or trace an individual's identity alone or when combined.
The OMB definition centers on information that can identify a specific individual.
33. What role does a Chief Privacy Officer (CPO) typically fulfill?
A. Manages the organization's public relations and marketing.
B. Is the most senior leader responsible for managing privacy risks and laws.
C. Heads the information technology infrastructure team.
D. Audits financial records for fraudulent activity.
B. Is the most senior leader responsible for managing privacy risks and laws.
The CPO oversees legal and regulatory compliance related to personal data privacy.
34. What is the principle of "full disclosure" in privacy regulations?
A. Companies must disclose all their security vulnerabilities to the public.
B. Individuals should know what information is collected and how it is used.
C. Employees must disclose personal relationships to HR.
D. IT departments must disclose network diagrams to auditors.
B. Individuals should know what information is collected and how it is used.
Transparency about data practices is a core tenet of privacy protection.
45
35. Data encryption is considered what type of security control?
A. A detective control
B. A preventive control
C. An administrative control
D. A corrective control
B. A preventive control
Encryption prevents unauthorized reading of data, acting as a preventive measure.
36. An organization's "risk appetite" refers to what?
A. The amount of loss it is willing to accept in normal business.
B. Its desire to take on more risk than its competitors.
C. The budget allocated for security insurance policies.
D. Employee enthusiasm for participating in security training.
A. The amount of loss it is willing to accept in normal business.
Risk appetite defines the threshold of acceptable risk exposure for the organization.
37. What is a danger of relying exclusively on quantitative risk scores?
A. They are always too expensive to calculate.
B. They may not replace qualitative human judgment and common sense.
C. They guarantee regulatory compliance once achieved.
D. They are easy for all employees to understand.
B. They may not replace qualitative human judgment and common sense.
Numbers can lag behind real-world changes and lack contextual insight.
38. Business liability emerges when an organization fails to meet what?
A. Its quarterly profit targets.
B. Its obligation or duty, legal or promised.
C. Employee salary increase expectations.
D. Technology refresh cycle deadlines.
B. Its obligation or duty, legal or promised.
Liability is tied to the failure to fulfill commitments, creating legal or trust risks.
39. What is a key step in minimizing liability from employee actions?
A. Never hiring employees with prior work experience.
B. Having clear policies and enforcing them with discipline.
46
C. Ensuring employees work from home to reduce office incidents.
D. Allowing employees to set their own security rules.
B. Having clear policies and enforcing them with discipline.
Enforcement and accountability create separation between rogue acts and organizational posture.
40. An Acceptable Use Policy (AUP) primarily describes what?
A. The brand of computers employees can use.
B. Employee behavior when using company computer and network systems.
C. The acceptable profit margins for company products.
D. How to request time off from work.
B. Employee behavior when using company computer and network systems.
AUPs formally define proper and improper use of organizational IT resources.
41. A Confidentiality Agreement (CA) or Non-Disclosure Agreement (NDA) is what?
A. A suggestion for how to handle public information.
B. A binding legal contract promising not to disclose covered information.
C. An internal memo about department meetings.
D. A policy that applies only to full-time employees, not contractors.
B. A binding legal contract promising not to disclose covered information.
These are legal instruments that protect sensitive information shared between parties.
42. What can business liability insurance help cover, even with good policies?
A. Guaranteed prevention of all security incidents.
B. Financial losses and legal fees from incidents within policy limits.
C. The cost of employee bonuses for good security behavior.
D. Expenses related to marketing new security products.
B. Financial losses and legal fees from incidents within policy limits.
Insurance is a risk transfer mechanism for financial consequences.
43. Operational consistency in security means processes are what?
A. Executed each time with the same consistency and quality.
B. Changed frequently to adapt to new threats.
C. Managed by different departments each quarter.
D. Documented but not necessarily followed.
47
A. Executed each time with the same consistency and quality.
Consistency enables reliability, quality improvement, and predictable risk management.
44. An enterprise view of risk allows leaders to understand what?
A. Only the risks in the IT department's budget.
B. How risk affects the entire organization, not just local parts.
C. Competitors' secret security strategies.
D. The personal risk tolerance of each employee.
B. How risk affects the entire organization, not just local parts.
It provides a holistic perspective, seeing systemic issues versus isolated events.
45. What oversight phase involves tracking defects, errors, and incidents?
A. Manage
B. Measure
C. Review
D. Track
D. Track
The Track phase involves monitoring failures and incidents for analysis.
46. A mitigating control does what?
A. Always achieves the full intent of the policy.
B. Limits damage caused by the absence or failure of a primary control.
C. Is required to be fully automated.
D. Replaces the need for a primary control entirely.
B. Limits damage caused by the absence or failure of a primary control.
It reduces impact after the fact but may not meet the original policy goal.
47. A compensating control is different because it does what?
A. Achieves the desired policy outcome, but potentially in a different way.
B. Is only used when no other controls are in place.
C. Focuses solely on detecting policy violations.
D. Applies only to physical security measures.
A. Achieves the desired policy outcome, but potentially in a different way.
It fulfills the policy intent through alternative means, maintaining the same level of risk reduction.
48
48. What is "residual risk"?
A. The risk that is eliminated by security controls.
B. The risk that remains after security controls have been applied.
C. The risk taken by the most senior executive.
D. The risk associated with residual data on hard drives.
B. The risk that remains after security controls have been applied.
No control is perfect; some risk always remains and must be managed or accepted.
49. A waiver or exception process should include consideration of what?
A. Only the benefits to the single business unit requesting it.
B. The residual risk and formal management acceptance of it.
C. Automatically approving all requests to maintain business speed.
D. Hiding the exception from auditors and regulators.
B. The residual risk and formal management acceptance of it.
The process must formally assess and get approval for any remaining risk.
50. What do security policies ultimately provide guidance on for daily decisions?
A. How to think about and manage risk in business operations.
B. The exact technical configuration for every system.
C. Which employees are allowed to work from home.
D. The company's stock market investment strategy.
A. How to think about and manage risk in business operations.
Policies frame risk management within the context of everyday business processes and choices.
Fill In Blank Spaces
51. Security policies let your organization set rules to reduce risks to __________.
information assets
Policies aim to protect the core information assets that support business operations.
52. A good security policy can reduce the __________ of a risk occurring or reduce its impact.
likelihood
Policies are a risk treatment option focused on reducing probability or consequence.
49
53. The 2013 Target data breach put at risk the financial information of an estimated __________ customers.
40 million
The scale of the breach highlights the massive impact of policy failures.
54. The Poneman Institute study found that 39 percent of data breaches were attributed to __________.
negligence
Human error, often due to poor policy adherence, is a significant cause of breaches.
55. For policies to be effective, they must be __________.
enforced
A policy without enforcement is merely a suggestion, not a control.
56. Security policy __________ means adhering to the rules set forth in security policies.
compliance
Compliance is the measurable state of following established policy directives.
57. The key to security policy is being able to measure compliance against a set of __________.
controls
Controls implement the policy, providing tangible points for measurement.
58. Vague or __________ policy statements create confusion and may lead to incorrect choices.
open-ended
Clarity is crucial to ensure consistent interpretation and application of policies.
59. A more accurate compliance measurement gives the business more __________ to understand its risks.
confidence
Accurate metrics lead to better risk-informed decision-making.
60. Security __________ are the means of enforcing security policies.
controls
Controls translate policy objectives into actionable, measurable safeguards.
61. Reducing the frequency of security policy __________ makes policies easier to enforce and train.
changes
Stability in policies aids in employee comprehension and consistent application.
62. A __________ control refers to a physical device that prevents or deters access.
physical
Physical controls are the first layer of defense in a comprehensive security model.
50
63. A __________ control relies on a human to take some action, like security training.
procedural or administrative
These controls govern the people and processes surrounding information systems.
64. A preventive control designed to stop an incident is typically an __________ control.
automated
Automation allows for immediate, consistent prevention without human latency.
65. A __________ control alerts an organization that an incident might have occurred.
detective
Detection is critical for response and for understanding the scope of a breach.
66. If human action is required, the control is considered __________.
manual
The need for human intervention defines a control as manual, even if partially automated.
67. A corrective control limits business impact by correcting the __________.
vulnerability
Corrective actions address the root cause or weakness that was exploited.
68. Security policies must drive a culture that mitigates __________.
risk exposure
The ultimate goal is to reduce the organization's overall exposure to potential harm.
69. A good security __________ program makes employees aware of expected behaviors.
awareness
Awareness is the foundational step in shaping a security-conscious workforce.
70. Security awareness programs have two enforcement components: the carrot and the __________.
stick
This represents positive reinforcement (rewards) and negative consequences (discipline).
71. A __________ culture shares a common set of values about the importance of managing risks.
risk-aware
This culture embeds risk consideration into everyday decision-making.
72. Intellectual property is any company information thought to bring a competitive __________.
advantage
IP's value lies in its potential to provide a business edge in the marketplace.
51
73. Protecting IP through security policies starts with __________ policies.
human resources (HR)
HR policies establish the foundational code of conduct and ownership rules for employees.
74. A __________ is typically a mark or comment placed inside a document itself, like "confidential."
label
Labeling is a visible method to indicate the sensitivity of information.
75. __________ is the process of placing a sensitive file in a secured location based on its sensitivity.
Data classification
Classification drives systematic handling and storage based on data criticality.
76. A widely accepted practice to prevent IP loss is to filter __________ for IP data.
e-mail and other communication tools
Monitoring outbound communications helps prevent inadvertent or malicious data exfiltration.
77. __________ are any digital content an organization owns or has the right to use.
Digital assets
This broad category includes text, graphics, audio, video, and animations.
78. The ability to protect digital assets starts with a good __________.
inventory
You cannot secure what you have not identified and located.
79. Applying data classification to __________ data, like personal files on a laptop, is a major challenge.
unstructured
Unstructured data lacks a predefined format, making systematic classification difficult.
80. __________ is information that can be used to distinguish or trace an individual's identity.
Personally Identifiable Information (PII)
PII is the core data requiring protection under privacy laws and regulations.
81. A __________ provides direction on legal requirements for handling PII data.
chief privacy officer (CPO)
This senior role is responsible for navigating the complex landscape of privacy regulations.
82. The principle of __________ gives consumers an understanding of what data is collected and how it is
used.
full disclosure
Transparency is a fundamental requirement of ethical and legal privacy practices.
52
83. __________ provides an additional layer of security by making data unreadable without a key.
Data encryption
Encryption protects data confidentiality even if other controls, like access controls, fail.
84. A company's __________ is how much loss it is willing to accept in normal business.
risk appetite
This threshold guides investment in security controls and acceptance of residual risk.
85. __________ occurs when a company fails to meet its obligation to employees and community.
Business liability
Liability extends beyond legal mandates to include social and ethical commitments.
86. An employer's failure to act on policy violations can create the impression it __________ the action.
condones
Inaction can imply tacit approval, increasing organizational liability.
87. __________ are formal written policies describing employee behavior on company systems.
Acceptable use policies (AUPs)
AUPs explicitly define the rules for using organizational IT resources.
88. A __________ is a binding legal contract between parties not to disclose covered information.
confidentiality agreement (CA) or nondisclosure agreement (NDA)
These legal instruments are critical for protecting sensitive information during collaborations.
89. Business liability __________ can pay for losses and legal fees within policy limits.
insurance
Insurance acts as a financial backstop, transferring some risk exposure.
90. __________ means ensuring an organization's processes are repeatable and sustainable.
Operational consistency
Consistency reduces variability, which in turn reduces unexpected risks and errors.
91. An __________ view allows leaders to see how risk affects the entire organization.
enterprise
This holistic perspective is necessary for effective, organization-wide risk management.
92. To achieve repeatable behavior, you must measure both consistency and __________.
quality
Quality ensures the process not only repeats but also achieves the desired outcome reliably.
53
93. A __________ control limits damage caused by not having a primary control in place.
mitigating
It is a secondary control that reduces impact after a primary control has failed or is absent.
94. A __________ control achieves the desired policy outcome but in a different way.
compensating
It provides an alternative method to meet the policy's objective and risk reduction goal.
95. __________ from policy may be necessary but should go through a formal waiver process.
Operational deviation
A managed process for exceptions ensures deviations are justified and risks are accepted.
96. __________ is the risk that remains after security controls have been applied.
Residual risk
All controls have limitations, leaving some level of risk that must be acknowledged and managed.
97. A waiver process should examine the risk to the entire organization, not just the local __________.
impact
Exceptions must be evaluated for their systemic, not just local, risk implications.
98. Proper approval for residual risk includes vetting with leaders who would be held __________.
accountable
Those ultimately responsible for the consequences must formally accept the remaining risk.
99. Policies encourage behavior that positively drives the organization's __________.
risk culture
Effective policies shape the shared attitudes and practices regarding risk management.
100. For business, it is daily __________ and decisions that control risk.
processes
Risk management is embedded in routine operations, not just periodic audits or projects.
True/False Questions
101. The goal of security policies is to eliminate all business risks.
False
It is impossible to eliminate all risk; policies aim to manage and reduce risk to an acceptable level.
54
102. Technology dependence has grown so rapidly that many business operations would stop without it.
True
The chapter states global business is deeply dependent on technology for operations.
103. A breach is defined as any attempt to access a network without permission.
False
A breach is a confirmed event that compromises confidentiality, integrity, or availability.
104. The cost of the Target data breach was less than $1 million.
False
Costs for companies involved reached upwards of $200 million.
105. Policies are effective only if they are enforced by management.
True
Enforcement is critical; unenforced policies are ineffective and can undermine credibility.
106. Developing policy statements on legal issues is simple and requires no legal review.
False
It is highly sensitive work that requires legal department review of draft wording.
107. Compliance means the same as having security controls in place.
False
Compliance means adhering to policies; controls are the mechanisms to achieve and measure that
adherence.
108. A simple measurement of compliance is always the most accurate approach.
False
Simple measurements can be misleading, as shown by the firewall traffic weighting example.
109. Security policies contain the specific technical details of security controls.
False
Policies define the why and what; controls define the how. They are treated separately.
110. A firewall is an example of an administrative security control.
False
A firewall is a technical (or logical) control, specifically a preventive one.
111. A preventive control is always an automated control.
False
A preventive control can be manual (e.g., a security guard checking IDs) or automated.
55
112. A detective control, by definition, prevents an incident from occurring.
False
Detective controls identify incidents after they occur; they do not prevent the initial event.
113. The "tone at the top" refers only to written policy statements from leadership.
False
It includes both words and actions taken by senior managers to implement and enforce policies.
114. If policies are optional, employees might treat them as simply guidelines.
True
Without mandatory enforcement, policies lose their authority and influence on behavior.
115. Security awareness training needs to be conducted only when an employee is hired.
False
Repetition is key; training should be refreshed regularly (e.g., annually) due to evolving risks.
116. A risk-aware culture means a culture that avoids taking any risks.
False
It means a shared understanding of the importance of managing risks, not avoiding them entirely.
117. Intellectual Property (IP) laws cover only patented inventions and copyrighted works.
False
IP laws broadly cover ideas, inventions, literary creations, business models, software code, and more.
118. Labeling data and classifying data are two terms for the exact same process.
False
Labeling marks the document; classification may involve securing it in a specific location.
119. Protecting digital assets is easy once you have a security policy.
False
Protection starts with a major challenge: creating and maintaining an accurate inventory of assets.
120. Personally Identifiable Information (PII) definitions are consistent across all U.S. states.
False
Different states have varying laws defining what constitutes PII and how it must be protected.
121. All organizations are required by federal law to have a Chief Privacy Officer.
False
The CPO position is established by organizations as needed to manage complex privacy obligations.
56
122. Full disclosure requires companies to reveal their security vulnerabilities to customers.
False
It requires disclosing what personal data is collected and how it will be used, not security flaws.
123. Encrypting data at rest is always technically possible and straightforward.
False
The chapter states encrypting data at rest can be complicated and is sometimes not technically possible.
124. An organization's risk appetite can be quantitatively expressed as a dollar amount.
True
Risk appetite can be expressed in financial terms, indicating acceptable loss levels.
125. Quantitative risk scores can perfectly replace human qualitative judgment.
False
Risk scores are based on historical factors and may not capture current, nuanced realities.
126. Business liability is a subset of an organization's overall risk exposure.
True
Liability refers specifically to risks from failing to meet obligations, within the broader exposure.
127. An employer is always legally responsible for any action taken by an employee.
False
Clear, enforced policies can help separate employer liability from rogue employee actions.
128. Acceptable Use Policies (AUPs) should be reviewed and updated to keep up with technology
changes.
True
AUPs must evolve to cover new technologies like mobile devices and wearables.
129. Confidentiality Agreements (CAs) are only used with external consultants, not employees.
False
CAs/NDAs are often used at the time of hire to bind employees regarding company information.
130. Business liability insurance will pay for losses even if the company committed illegal acts.
False
Policies typically have exclusions and do not protect a company that has committed illegal acts.
131. Operational consistency aims to make business processes different each time they are executed.
False
It aims for processes to be repeatable and executed with the same consistency and quality.
57
132. An enterprise view of risk focuses on optimizing individual department performance.
False
An enterprise view looks at the entire organization to understand systemic risk.
133. Measuring whether a policy achieves desired results is unimportant for operational consistency.
False
Measurement of results is a key oversight phase to ensure processes provide value.
134. A mitigating control always achieves the full intent of the security policy.
False
A mitigating control limits damage but may not fully meet the policy's original objective.
135. A compensating control achieves the policy intent, but potentially through different means.
True
It provides equivalent risk reduction, fulfilling the policy goal via an alternative method.
136. Operational deviation from security policy should never be allowed under any circumstances.
False
A formal waiver process exists to manage necessary deviations with proper risk approval.
137. The purpose of a waiver process is to automatically approve all exception requests.
False
Its purpose is to independently examine business rationale, impact, and residual risk.
138. Residual risk must be formally accepted by management when exceptions are granted.
True
Accountability requires leaders to acknowledge and accept any remaining risk.
139. Security policies provide guidance on how to think about risk in daily business decisions.
True
Policies frame risk considerations within the context of operational choices.
140. A strong risk culture eliminates the need for any written security policies.
False
A risk culture is supported by, and manifested through, clear and enforced written policies.
Flashcards / Rapid Review Items
141. Define: Business Driver
A factor that influences organizational strategy, such as cost, customer satisfaction, or compliance.
58
142. Define: Security Breach
A confirmed event that compromises the confidentiality, integrity, or availability of information.
143. Define: Security Policy Compliance
Adherence to the rules and requirements set forth in an organization's security policies.
144. Define: Security Control
A mechanism (physical, administrative, or technical) designed to enforce security policies.
145. Define: Preventive Control
A control designed to stop an incident or breach from occurring.
146. Define: Automated Control
A control containing logic in software to decide actions without requiring human intervention.
147. Define: Detective Control
A control that alerts the organization that an incident might have occurred.
148. Define: Manual Control
A control that relies on human action to decide or implement a response.
149. Define: Corrective Control
A control that limits impact by correcting a vulnerability or restoring operations.
150. Define: Tone at the Top
Senior management's demonstrated commitment to and enforcement of security policies.
151. Define: Security Awareness Program
An initiative to make employees aware of expected behaviors regarding information security.
152. Define: Risk Culture
A culture that shares a common set of values, beliefs, and knowledge about managing risks.
153. Define: Intellectual Property (IP)
Any unique product of human intellect with marketplace value, giving a business advantage.
154. Define: Data Label
A mark or comment placed on a document to indicate its required level of protection.
155. Define: Data Classification
The process of categorizing data based on sensitivity and applying appropriate handling rules.
156. Define: Digital Assets
Any digital content (text, graphics, audio, video) owned or legally acquired by an organization.
59
157. Define: Personally Identifiable Information (PII)
Information that can distinguish or trace an individual's identity alone or when combined.
158. Define: Chief Privacy Officer (CPO)
The senior leader responsible for managing an organization's privacy risks and legal compliance.
159. Define: Full Disclosure
The privacy principle that individuals should know what data is collected and how it is used.
160. Define: Data Encryption
A preventive control that uses cryptographic techniques to make data unreadable without a key.
161. Define: Risk Appetite
The amount of loss an organization is willing to accept in the normal course of business.
162. Define: Business Liability
The state of being legally or ethically responsible for failing to meet an obligation.
163. Define: Acceptable Use Policy (AUP)
A formal policy describing proper and improper employee behavior on company IT systems.
164. Define: Confidentiality Agreement (CA)/Non-Disclosure Agreement (NDA)
A binding legal contract where parties promise not to disclose specified information.
165. Define: Operational Consistency
Ensuring organizational processes are repeatable, sustainable, and executed with quality.
166. Define: Enterprise View
A holistic perspective understanding how risk affects the entire organization.
167. Define: Mitigating Control
A control that limits damage caused by the absence or failure of a primary control.
168. Define: Compensating Control
A control that achieves the desired policy outcome through alternative means.
169. Define: Operational Deviation
A departure from established policy during the execution of a business process.
170. Define: Residual Risk
The risk that remains after all security controls have been applied.
171. Identify: One example of a physical control.
A locked door, security camera, electric fence, or security guard.
60
172. Identify: One example of an administrative control.
Security awareness training or a manager reviewing an employee's work.
173. Identify: One example of a technical control.
A password system, antiviral software, or a firewall.
174. Identify: The three unique security control design types.
Preventive, detective, and corrective.
175. Identify: The two enforcement components of a security awareness program.
The carrot (positive reinforcement) and the stick (negative consequences).
176. Identify: A starting point for protecting intellectual property via policy.
Human Resources (HR) policies that establish a code of conduct.
177. Identify: A major implementation issue for protecting digital assets.
Creating and maintaining an accurate inventory of where data resides.
178. Identify: A recommended mode for testing automated classification tools.
Log mode, which records actions without implementing them.
179. Identify: Two important principles involved in privacy regulations.
Full disclosure and data encryption.
180. Identify: A subset of overall risk exposure related to unmet obligations.
Business liability.
181. Identify: A key tool to create legal separation between employer and employee actions.
An enforced Acceptable Use Policy (AUP).
182. Identify: A risk transfer mechanism for financial losses from incidents.
Business liability insurance.
183. Identify: The four typical oversight phases for operational consistency.
Manage, Measure, Review, and Track (with Improve being a continuous goal).
184. Identify: Who should approve residual risk when a policy exception is granted.
The leaders who would be held accountable if the risk is realized.
185. Identify: What policies provide guidance on for daily business decisions.
How to think about and manage risk.
186. Purpose: Why are business drivers important for security policies?
Policies must balance competing drivers like cost, satisfaction, and compliance.
61
187. Purpose: What is the role of management in policy creation?
To avoid surprises regarding cost or operational impact and ensure business relevance.
188. Purpose: Why measure compliance against controls?
To validate that policy requirements have been applied and are effective.
189. Purpose: Why treat policies and controls separately?
To allow controls to evolve with technology while keeping policy goals stable.
190. Purpose: What is the goal of a security awareness program?
To educate employees on expected behaviors and the importance of security policies.
Application-Based Questions
191. A retail company's data classification policy labels all transaction logs as "Restricted." An analyst
needs to copy a week's logs to a USB drive for analysis at a secure offsite location. According to policy,
what must the analyst likely do before copying the data?
A. Delete older logs to save space on the USB drive.
B. Obtain manager approval and encrypt the data on the USB drive.
C. Share the logs with the IT department for feedback first.
D. Print the logs and carry the paper copies instead.
B. Obtain manager approval and encrypt the data on the USB drive.
Handling "Restricted" data likely requires authorization and encryption for off-network transport, aligning
with data protection principles.
192. During a security audit, it is found that a critical server is missing a required security patch due to
an oversight. The unpatched vulnerability represents a high risk. What type of control would an automated
patch management system represent in this scenario?
A. A corrective control
B. A detective control
C. A preventive control
D. A mitigating control
C. A preventive control
An automated patch management system is designed to prevent incidents by proactively fixing
vulnerabilities before they can be exploited.
62
193. A financial firm's policy states all client communications must be archived. A review finds 90% of
emails are archived automatically, but 10% from a specific department are missing due to a software
configuration error. What does this finding illustrate about compliance measurement?
A. The firm is 90% compliant, which is fully acceptable.
B. Simple percentage measurements can mask significant non-compliance in specific areas.
C. The policy should be abandoned because it is not 100% effective.
D. The missing 10% is irrelevant because it's a small volume.
B. Simple percentage measurements can mask significant non-compliance in specific areas.
The 10% gap, though small in percentage, could represent a major liability if it involves sensitive client
communications, showing the limitation of simple metrics.
194. An employee receives a phishing email that mimics the CEO's request for urgent wire transfer. The
employee, recalling recent security training, notices slight discrepancies in the sender's address and
reports it to the IT help desk. Which security control component was most effective here?
A. The preventive technical control of the email spam filter.
B. The detective automated control of the network intrusion detection system.
C. The corrective control of the incident response plan.
D. The administrative control of the security awareness training.
D. The administrative control of the security awareness training.
The human action taken by the employee, informed by training (an administrative control), was key in
detecting and reporting the threat.
195. A company wants to share preliminary product designs with a potential manufacturing partner.
Before any information is exchanged, what should the company's security policy typically require?
A. The partner must use the same brand of computer aided design (CAD) software.
B. Both parties must sign a Confidentiality Agreement (CA) or Non-Disclosure Agreement (NDA).
C. The company must first publish the designs on its website.
D. The partner must provide a list of all its employees.
B. Both parties must sign a Confidentiality Agreement (CA) or Non-Disclosure Agreement (NDA).
A CA/NDA is a standard legal instrument to protect intellectual property before sharing sensitive information
with external parties.
196. A healthcare provider's policy mandates encryption for all patient data on mobile devices. A nurse
needs to access a patient's treatment history on a tablet during rounds. The tablet is lost. Why does this
63
policy limit the organization's liability?
A. The loss is now only the nurse's personal responsibility.
B. The encrypted data is unreadable, mitigating the breach's impact and demonstrating due care.
C. It automatically notifies patients that their data was lost.
D. It guarantees the tablet will be found quickly.
B. The encrypted data is unreadable, mitigating the breach's impact and demonstrating due care.
Encryption acts as a preventive control that reduces the severity of the incident, showing the organization
took reasonable steps to protect data.
197. An audit reveals that employees in the finance department are using unauthorized cloud storage
apps to share large files, bypassing the slower approved system. This violates the AUP. What should
management do to minimize organizational liability?
A. Ignore it because the employees found a more efficient workaround.
B. Praise the employees for their initiative and upgrade the approved system later.
C. Enforce the AUP by disciplining violators and communicating the rationale for the policy.
D. Immediately block all Internet access for the finance department.
C. Enforce the AUP by disciplining violators and communicating the rationale for the policy.
Enforcement and clear communication demonstrate the organization does not condone policy violations,
separating the company from rogue employee actions.
198. A business unit requests an exception to the password complexity policy for a legacy application
that cannot support it. The security team proposes implementing a two-factor authentication token as an
alternative. This alternative is best described as what?
A. A mitigating control
B. A detective control
C. A compensating control
D. A redundant control
C. A compensating control
Two-factor authentication achieves the policy intent of strong authentication (assuring identity) through a
different method than complex passwords, thus compensating for the technical limitation.
199. During a merger, Company A discovers that Company B has no formal data classification policy.
Company A's policy has three tiers: Public, Internal, and Confidential. What is a critical first step for
applying Company A's policy to Company B's data?
64
A. Immediately delete all data labeled as "Public" from Company B.
B. Conduct an inventory to identify and categorize Company B's digital assets.
C. Apply the "Confidential" label to all of Company B's data to be safe.
D. Mandate that all Company B employees memorize the new policy.
B. Conduct an inventory to identify and categorize Company B's digital assets.
You cannot classify or protect data you have not identified. Inventory is the foundational step for applying
any data protection policy.
200. The CFO asks why the company needs a "Chief Privacy Officer" when it already has a Legal
department. The best explanation, based on the role's definition, is that the CPO:
A. Manages the company's public financial reporting.
B. Is the senior leader specifically focused on privacy laws and managing associated risks.
C. Replaces the need for external legal counsel.
D. Handles customer service complaints.
B. Is the senior leader specifically focused on privacy laws and managing associated risks.
The CPO role provides dedicated, senior-level focus on the complex and evolving landscape of privacy
regulations and their business impact.
201. A software development team adopts a new agile project management tool hosted by a third-party
vendor. The tool will store source code and bug reports. What should the company's security policy require
before the team can use this tool?
A. The team must promise not to store any important code there.
B. The vendor must agree to a Confidentiality Agreement (CA) covering the data.
C. The team leader must approve the tool's color scheme.
D. All developers must complete a marathon coding session.
B. The vendor must agree to a Confidentiality Agreement (CA) covering the data.
Before exposing intellectual property (source code) to a third-party system, a CA/NDA is essential to legally
bind the vendor to protect that information.
202. An organization's "risk appetite" statement indicates it will accept up to $100,000 in annual losses
from fraud. Fraud detection costs are projected to be $150,000 per year. Based on this, what is the most
governance-aligned decision?
A. Implement the detection system because any fraud is unacceptable.
B. Do not implement the system, as the cost exceeds the accepted loss threshold.
65
C. Implement the system but only in the highest-risk department.
D. Fire the manager who calculated the fraud loss projections.
B. Do not implement the system, as the cost exceeds the accepted loss threshold.
Risk appetite guides investment; if control costs are higher than the value of the risk being mitigated, it may
not be a prudent investment.
203. A policy states that all servers must be located in a physically access-controlled data center. A
research team needs to place a server in their lab for a short-term experiment. They submit a waiver
request. What must the waiver approval process definitively establish?
A. The residual risk and obtain formal management acceptance of it.
B. That the research team will be solely liable for any incident.
C. That the policy is wrong and should be changed.
D. That the server will be disguised as a piece of furniture.
A. The residual risk and obtain formal management acceptance of it.
The waiver process must quantify the risk of not following the policy and get documented approval from
accountable leaders for accepting that risk.
204. A company prides itself on its "risk-aware culture." In practice, this would most likely be observed
when:
A. Employees hide mistakes to avoid getting in trouble.
B. An employee, unsure if an attachment is safe, reports it to security instead of opening it.
C. Each department creates its own unique password policy.
D. Security policies are kept secret from most employees.
B. An employee, unsure if an attachment is safe, reports it to security instead of opening it.
A risk-aware culture encourages proactive, security-conscious behavior and using available resources
when faced with uncertainty.
205. A detective control alerts the security team to repeated failed login attempts on an executive's
account from a foreign country. The account is temporarily locked. What type of control is the account
lockout?
A. A preventive control
B. A detective control
C. A corrective control
D. A physical control
66
C. A corrective control
The lockout corrects the immediate vulnerability (the potentially compromised account) by preventing
further access attempts, limiting potential impact.
206. A policy requires quarterly review of administrator activity logs. The manager responsible has not
reviewed the logs for the past two quarters due to other priorities. This situation primarily represents a
failure of what?
A. A technical control
B. A preventive control
C. An administrative control
D. A compensating control
C. An administrative control
The required manual review is an administrative control. The failure to perform the review is a breakdown in
that control's execution.
207. An organization wants to lower its risk exposure related to phishing. According to the chapter's
principles, which approach combines people, process, and technology effectively?
A. Deploying email filtering software (technology) only.
B. Implementing a security awareness program (people/process) with simulated phishing tests
(measurement).
C. Blocking all external emails (technology) only.
D. Issuing a memo telling employees to be careful (process) only.
B. Implementing a security awareness program (people/process) with simulated phishing tests
(measurement).
A combined approach educates employees (people/process) and tests their knowledge (measurement),
addressing the human element of the risk.
208. A business continuity plan that includes restoring data from backups after a ransomware attack is
primarily an example of what?
A. A preventive control aiming to stop the attack.
B. A detective control aiming to identify the attack.
C. A corrective control aiming to recover from the attack.
D. A mitigating control for weak passwords.
67
C. A corrective control aiming to recover from the attack.
Data restoration is a classic corrective action to recover operations after an incident has occurred.
209. In the context of data protection, what is the primary purpose of putting "Confidential" in the footer
of a document?
A. To automatically encrypt the document.
B. To serve as a data label informing handlers of its sensitivity.
C. To reduce the file size of the document.
D. To make the document look more official.
B. To serve as a data label informing handlers of its sensitivity.
The footer text acts as a persistent label, communicating the required level of protection to anyone who
views the document.
210. If a security policy is found to be so complex that employees consistently misunderstand it, the
most direct impact is that:
A. Security controls built from the policy will likely be reliable.
B. The policy cannot be used to build reliable, consistent security controls.
C. The policy should be made even longer to add more clarification.
D. Automated controls will perfectly compensate for the confusion.
B. The policy cannot be used to build reliable, consistent security controls.
Unclear policy leads to inconsistent interpretation, making it impossible to design controls that uniformly
enforce the intended rules.
211. A company's data retention policy requires destroying customer PII two years after account
closure. An employee keeps a local spreadsheet with old customer data for "future reference." This action
creates liability primarily because:
A. It violates the retention policy and could lead to a privacy breach.
B. Spreadsheets are not an approved corporate tool.
C. The employee did not get the spreadsheet approved by marketing.
D. It uses too much disk space on the laptop.
A. It violates the retention policy and could lead to a privacy breach.
Keeping PII beyond its authorized retention period increases exposure and liability in the event of a data
loss, violating policy and potentially the law.
68
191. The principle that security policies should be "relevant to business needs" suggests that a policy is
more likely to be followed if it:
A. Is written in the most technical language possible.
B. Clearly explains how it supports a business goal, like protecting customer trust.
C. Is longer than 20 pages to cover all contingencies.
D. Applies only to the IT department, not other staff.
B. Clearly explains how it supports a business goal, like protecting customer trust.
When employees understand the business rationale behind a rule, they are more likely to perceive it as
valuable and comply.
192. When an organization measures compliance by reviewing logs of high-risk activities only, it is
implicitly making what assumption?
A. Logging every employee action is technically feasible.
B. High-risk activities represent the areas of greatest potential impact if policy fails.
C. Low-risk activities never lead to security incidents.
D. Employees in low-risk roles do not need training.
B. High-risk activities represent the areas of greatest potential impact if policy fails.
Resource constraints necessitate a risk-based approach, focusing measurement on activities that could
cause the most harm.
193. A manual control where a manager must approve all wire transfers over $10,000 is primarily what
type of control?
A. A preventive manual control
B. A detective automated control
C. A corrective technical control
D. A mitigating physical control
A. A preventive manual control
The approval step is designed to prevent fraudulent or erroneous transfers before they occur, and it
requires human action.
194. The concept of "operational consistency" in security is most directly threatened by:
A. Having a well-documented, standard process for onboarding new employees.
B. Allowing each department to handle customer data in its own unique way.
C. Using centralized tools to deploy security settings to all laptops.
69
D. Reviewing security metrics in a standard monthly management report.
B. Allowing each department to handle customer data in its own unique way.
Inconsistent processes introduce variability, making risks harder to detect, measure, and manage across
the organization.
195. A compensating control is most appropriate to consider during which organizational process?
A. When writing a new policy from scratch.
B. When granting a formal exception to an existing policy.
C. When terminating an employee for policy violation.
D. When selecting a vendor for office supplies.
B. When granting a formal exception to an existing policy.
When a policy cannot be followed, compensating controls provide an alternative way to achieve the same
risk reduction goal, which is evaluated during the exception/waiver process.
196. A company with a strong "tone at the top" regarding security would likely have senior leaders who:
A. Are exempt from attending security awareness training.
B. Publicly emphasize the importance of security and complete training themselves.
C. Delegate all security decisions to the IT manager.
D. View security spending as a waste of resources.
B. Publicly emphasize the importance of security and complete training themselves.
Leadership demonstrates commitment through their own actions (like taking training) and consistent
communication of priorities.
197. An inventory scan discovers unencrypted files containing Social Security Numbers on a
department's shared drive, violating policy. The immediate next step dictated by policy governance should
be to:
A. Ignore them, as they were found on a secure internal drive.
B. Delete the files immediately without notifying anyone.
C. Classify/encrypt the files and investigate how the policy violation occurred.
D. Reward the department for storing data centrally.
C. Classify/encrypt the files and investigate how the policy violation occurred.
The discovery triggers a corrective action (fixing the vulnerability) and a detective/analytic process to
understand the root cause for improvement.
70
198. The relationship between security policies and business risk is that well-defined policies:
A. Eliminate the need for business risk analysis.
B. Provide rules and guidance to help reduce information-related business risks.
C. Increase business risk by slowing down operations.
D. Are only concerned with technical IT risks, not business outcomes.
B. Provide rules and guidance to help reduce information-related business risks.
Policies are a management tool designed to address and mitigate risks that could harm the business
through its information assets.
199. In the firewall compliance example from the chapter, the more accurate measurement considered
the percentage of Internet traffic. This highlights that effective measurement must account for:
A. The color of the firewall hardware.
B. The relative importance or impact of the non-compliant element.
C. The seniority of the firewall administrator.
D. The brand of the firewall software.
B. The relative importance or impact of the non-compliant element.
A weighted measurement based on impact (like traffic volume) provides a truer picture of risk exposure
than a simple count of devices.
200. If a security awareness program only uses "the stick" (disciplinary consequences), it is likely to be
less effective because it lacks:
A. Sufficient complexity.
B. Positive reinforcement and education ("the carrot").
C. Involvement from the legal department.
D. A written policy to back it up.
B. Positive reinforcement and education ("the carrot").
A balanced program using both positive and negative motivators is more successful in fostering a
sustainable, positive security culture.
201. The chapter suggests that a policy exception (waiver) should be reviewed by a team independent
of the requesting business unit. Why is independence important?
A. To ensure the review is biased in favor of the business unit's goals.
B. To guarantee the exception is approved quickly without scrutiny.
C. To provide an objective assessment of risk to the entire organization.
71
D. To allow the security team to avoid making difficult decisions.
C. To provide an objective assessment of risk to the entire organization.
Independence reduces conflict of interest and ensures the evaluation focuses on enterprise-wide risk, not
just local convenience.
202. When data is classified by the location where it is stored (e.g., "all data on laptops is classified as
Internal"), rather than by individual file content, this is often a response to what challenge?
A. The challenge of encrypting data on laptops.
B. The challenge of applying classification to vast amounts of unstructured data.
C. The challenge of hiring a Chief Privacy Officer.
D. The challenge of writing an Acceptable Use Policy.
B. The challenge of applying classification to vast amounts of unstructured data.
Location-based classification is a practical, if less precise, technique when file-level classification is too
complex or resource-intensive.
203. A qualitative judgment about risk is most valuable when it:
A. Ignores numerical risk scores entirely.
B. Complements quantitative scores with experience and common sense.
C. Is made exclusively by junior staff members.
D. Is never documented to allow for flexibility.
B. Complements quantitative scores with experience and common sense.
Qualitative judgment incorporates context, intuition, and real-world insight that pure numbers may miss,
leading to better risk decisions.
204. The final step in the chapter's described oversight phases for operational consistency is "Improve."
This implies that policy management should be:
A. A static, one-time project.
B. A continuous cycle of measurement, review, and adjustment.
C. The sole responsibility of external auditors.
D. Focused only on major, catastrophic risks.
B. A continuous cycle of measurement, review, and adjustment.
Continuous improvement is essential for adapting policies and controls to changing threats, technologies,
and business needs.
72
205. A new regulation requires stronger protection for a specific type of customer data. To maintain
compliance, the organization must first:
A. Fire its legal counsel.
B. Update its relevant security policies to reflect the new requirement.
C. Immediately buy the most expensive security product on the market.
D. Ignore the regulation until fined.
B. Update its relevant security policies to reflect the new requirement.
Policies are the formal statement of organizational rules. They must be updated first to provide the authority
and direction for any subsequent control changes.
206. An employee finds a USB drive in the parking lot and plugs it into their work computer to identify
the owner, against policy. The drive contains malware. The subsequent infection primarily demonstrates a
failure in which control type?
A. Preventive (policy against using unknown media)
B. Detective (antivirus software)
C. Corrective (system restoration procedures)
D. Compensating (network segmentation)
A. Preventive (policy against using unknown media)
The policy itself is a preventive administrative control. The employee's violation of that policy allowed the
threat to be introduced.
207. The chapter uses the analogy of making a paper airplane versus an origami swan to illustrate that
policies should be:
A. As complex as possible to cover all details.
B. Simple and easy to understand for successful adoption.
C. Taught only to managers, not all employees.
D. Considered an art form, not a science.
B. Simple and easy to understand for successful adoption.
Complex, lengthy policies are difficult to comprehend, train on, and enforce across a large workforce.
208. For a policy to successfully "set the tone at the top," it is crucial that senior management's actions:
A. Are separate from the written policies.
B. Contradict the policies to show independence.
C. Align with and reinforce the policies they approve.
73
D. Focus solely on financial results.
C. Align with and reinforce the policies they approve.
Credibility and culture are built when leadership's behavior is consistent with the policies they mandate for
others.
209. When calculating risk exposure, why is it hard to include "reputation damage" in purely financial
terms?
A. Reputation damage has no real impact on a business.
B. The financial impact of lost trust and future sales is difficult to quantify precisely.
C. Insurance always covers reputation damage fully.
D. It is easily calculated using last year's sales figures.
B. The financial impact of lost trust and future sales is difficult to quantify precisely.
Reputational harm affects intangible assets like brand value and customer loyalty, which are challenging to
translate into immediate, certain dollar losses.
210. A company's data classification policy defines "Public" information. According to privacy principles,
a person's home address could be considered a public record in one state but not another. This illustrates
that policies must:
A. Ignore state laws and follow federal law only.
B. Be adaptable to the varying legal definitions of the locations where they operate.
C. Classify all home addresses as "Confidential" universally.
D. Prohibit the collection of home addresses entirely.
B. Be adaptable to the varying legal definitions of the locations where they operate.
To maintain compliance, policies must account for the specific regulatory requirements of each jurisdiction
the business operates in.
211. The "business context" of a security policy is important because knowing it helps:
A. Write policies using the most technical jargon.
B. Keep competing priorities like security and operations in balance.
C. Ensure policies are never changed once written.
D. Keep policies secret from most employees.
B. Keep competing priorities like security and operations in balance.
Understanding why a business process exists allows for the creation of security policies that protect it
without unnecessarily hindering its function.
74
212. A security control that is "not effective when it cannot distinguish between good and bad behavior"
is most likely suffering from a problem of:
A. Excessive cost.
B. Poor placement (physical vs. technical).
C. Overly broad or imprecise design.
D. Being manual instead of automated.
C. Overly broad or imprecise design.
A control that generates too many false positives or blocks legitimate activity lacks precision and becomes
a hindrance, reducing its effectiveness and adherence.
213. The chapter states that an organization's security policies, taken collectively, show its:
A. Financial profitability.
B. Commitment to protect information.
C. Preference for one technology vendor over another.
D. Organizational hierarchy chart.
B. Commitment to protect information.
The suite of policies demonstrates to employees, customers, and regulators the seriousness with which the
organization treats information protection.
214. In the event of a security incident, having well-documented and enforced policies primarily helps
the organization by:
A. Guaranteeing that no data was actually lost.
B. Providing a basis to defend its actions as reasonable and diligent.
C. Shifting all blame to the IT department.
D. Automatically triggering insurance payouts without investigation.
B. Providing a basis to defend its actions as reasonable and diligent.
Demonstrable due care through policies and enforcement is critical for legal and regulatory defense, even if
an incident occurs.
215. If a policy requires "strong authentication," but the technology to implement it changes, what is the
benefit of separating the policy from the control?
A. The policy must be rewritten every time technology changes.
B. The control can be updated to new technology while the policy goal remains.
C. Both policy and control must remain static to avoid confusion.
75
D. It allows the policy to become obsolete more quickly.
B. The control can be updated to new technology while the policy goal remains.
Separation allows for technological agility. The "what" (strong authentication) stays constant, while the
"how" (biometrics, tokens, etc.) can evolve.
216. A "risk-aware culture" translates into an increased likelihood of policies being followed because:
A. Employees are constantly afraid of being fired.
B. Following rules and supporting security becomes second nature.
C. Security policies are optional in such a culture.
D. IT monitors every keystroke employees make.
B. Following rules and supporting security becomes second nature.
In a positive risk culture, secure behavior is internalized as a normal part of doing one's job correctly, not as
an external imposition.
217. The guidance to "examine local state and federal requirements" when developing PII policy is
aimed at ensuring:
A. Policy complexity is maximized.
B. The policy is compliant with all applicable laws.
C. The policy is shorter than competitors' policies.
D. Only the federal government can audit the company.
B. The policy is compliant with all applicable laws.
The foundational purpose of a PII policy is to meet legal and regulatory obligations, which vary by
geography.
218. An effective security awareness program should ultimately teach an employee what to do when
encountering something suspicious. This is best summarized as teaching them:
A. To ignore it to avoid causing a false alarm.
B. Where to go for help or how to report the issue.
C. To solve all security problems on their own.
D. That suspicious activity is probably not important.
B. Where to go for help or how to report the issue.
The goal is to empower employees to act appropriately by providing clear pathways for reporting, not to
make them security experts.
76
219. The chapter concludes that for business, it is daily processes and decisions that control risk.
Therefore, effective security policies must be:
A. Abstract documents stored away from operational staff.
B. Integrated into and guide daily processes and decisions.
C. Reviewed only during annual audit periods.
D. Focused exclusively on long-term strategic planning.
B. Integrated into and guide daily processes and decisions.
Since risk manifests in daily operations, policies must be practical tools that employees use to make risk-
informed choices every day.
77
Associated Class Text
Johnson, R., & Easttom, C. (2021). Security policies and implementation issues (3rd ed.). Jones & Bartlett
Learning.