Flashcards
(2025-2026)
Question and Answers
Expert Verified
(With A+ Grades Guarantee)
,What is the primary objective of information security To align information security strategies with business objectives to deliver value and
governance? manage risk.
Who holds the ultimate accountability for an organization's The Board of Directors and executive management.
information security?
What is the primary function of an Information Security To ensure alignment of the security program with business objectives, review major
Steering Committee? security projects, and secure necessary resources.
Who should ideally chair the Information Security Steering A senior business executive (e.g., COO or CEO), not the CISO or CIO, to ensure
Committee? business alignment.
What is an Information Security Policy? A high-level document that states management's intent, expectations, and direction
regarding information security.
How does a Security Standard differ from a Security A policy states high-level intent, whereas a standard dictates specific, mandatory
Policy? technical controls and hardware/software baselines.
What is the purpose of a Security Guideline? To provide recommended, discretionary advice and best practices to help users
comply with mandatory standards.
What is a Security Procedure? A highly detailed, step-by-step instruction manual for executing a specific
operational task (e.g., configuring a firewall).
What is "Risk Appetite"? The broad, overarching amount of risk an organization is willing to accept in pursuit
of its strategic business objectives.
What is "Risk Tolerance"? The acceptable level of tactical variation around a specific objective or risk appetite
(the operational threshold).
What is "Risk Capacity"? The absolute maximum amount of risk an organization can physically or financially
absorb before facing catastrophic failure or bankruptcy.
Define "Inherent Risk". The raw, initial level of risk that exists before any security controls or mitigating
actions are applied.
Define "Residual Risk". The remaining level of risk that exists after all planned mitigating security controls
have been effectively implemented.
What is the fundamental goal of Risk Management? To reduce risk to an acceptable level that aligns perfectly with the organization's
formal Risk Appetite.
What are the four primary Risk Treatment strategies? Risk Mitigation, Risk Acceptance, Risk Avoidance, and Risk Transfer (Sharing).
,What does "Risk Mitigation" entail? Applying security controls and safeguards to reduce the likelihood or impact of a
specific threat.
What does "Risk Avoidance" entail? Completely ceasing or altering the business activity that generates the risk, thereby
eliminating the risk vector entirely.
What does "Risk Transfer" entail? Shifting the financial impact of a risk to a third party, most commonly through
purchasing cyber liability insurance or outsourcing.
What does "Risk Acceptance" entail? A formal, documented executive decision to proceed with an activity without adding
controls because the cost of mitigation exceeds the potential loss.
What is an "Orphan Risk"? An identified risk that has not been formally assigned an executive Risk Owner,
meaning it will likely go unmanaged.
What is a "Key Risk Indicator" (KRI)? A proactive, leading metric that provides an early warning signal that risk exposure
is increasing before an actual incident occurs.
What is a "Key Performance Indicator" (KPI)? An operational metric that measures how efficiently and effectively a specific
security process or control is performing.
What is a "Key Goal Indicator" (KGI)? A lagging, strategic metric that measures whether a specific business objective or
overarching security goal has been successfully achieved.
What is the primary advantage of Quantitative Risk It provides precise, financially justifiable metrics (dollar values) that executives can
Analysis? easily use for cost-benefit analyses.
What is the primary limitation of Quantitative Risk It requires massive amounts of accurate, statistically significant historical data,
Analysis? which is often unavailable for new cyber threats.
What is the primary advantage of Qualitative Risk It is fast, easy to understand, and relies on expert judgment to prioritize risks when
Analysis? hard numerical data is unavailable.
What is the "Delphi Method" in risk analysis? A qualitative technique that gathers anonymous input from a panel of experts over
multiple rounds to reach a consensus, eliminating groupthink and intimidation.
How is Single Loss Expectancy (SLE) calculated? Asset Value (AV) multiplied by the Exposure Factor (EF).
What does the Exposure Factor (EF) represent? The percentage of the asset's total value that would be destroyed or lost during a
single realization of a specific threat.
How is Annualized Loss Expectancy (ALE) calculated? Single Loss Expectancy (SLE) multiplied by the Annualized Rate of Occurrence
(ARO).
, What does the Annualized Rate of Occurrence (ARO) The estimated number of times a specific threat is expected to successfully occur
represent? within a single year.
How do you calculate the Return on Security Investment (Risk Exposure Mitigated - Cost of Control) / Cost of Control.
(ROSI)?
What is the COBIT framework primarily used for? The governance and management of enterprise IT, ensuring IT investments
generate business value and risks are optimized.
What is the SABSA framework? A business-driven, top-down enterprise security architecture framework designed to
integrate security seamlessly into business processes.
What is the primary focus of the ISO/IEC 27001 standard? Establishing, implementing, maintaining, and continually improving an Information
Security Management System (ISMS).
In ISO 27001, what is the Statement of Applicability (SoA)? A mandatory document detailing exactly which of the standard's Annex A controls
the organization has chosen to implement and the justification for doing so.
What are the five core functions of the NIST Cybersecurity Identify, Protect, Detect, Respond, and Recover.
Framework (CSF)?
What is the primary objective of Third-Party Risk To identify, assess, and continuously monitor the cybersecurity risks introduced by
Management (TPRM)? external vendors, suppliers, and partners.
Why is a "Right-to-Audit" clause critical in vendor It legally empowers the hiring organization to independently verify the vendor's
contracts? continuous compliance with security baselines over the life of the contract.
What does a SOC 2 Type I report evaluate? The design and suitability of a service organization's security controls at one
specific, static point in time.
What does a SOC 2 Type II report evaluate? The operational effectiveness of a service organization's security controls over a
sustained period of time (typically 6 to 12 months).
What is "Nth-Party Concentration Risk" (Systemic Risk)? The severe risk created when multiple independent vendors all rely on the exact
same underlying infrastructure (like a single cloud provider), creating a single point
of failure.
What is the "Confidentiality" pillar of the CIA Triad? Ensuring that sensitive information is strictly protected from unauthorized disclosure
or viewing.
What is the "Integrity" pillar of the CIA Triad? Ensuring that data remains accurate, complete, and mathematically unaltered by
unauthorized individuals or corruption during storage and transit.
What is the "Availability" pillar of the CIA Triad? Ensuring that authorized users have timely, reliable, and uninterrupted access to
data and resources exactly when they need them.