SECURITY MANAGEMENT PRACTICES EXAM THREE
UPDATED ACTUAL QUESTIONS AND CORRECT
ANSWERS
Question:
Define:
Gap Analysis
Information Security Framework
Answer:
Gap Analysis: It is a Technique for determining the steps to be taken in moving
from current state to desired future state.
Information Security Framework: Is a defined set of components used to design,
manage, and measure an information security program.
Question:
What is the difference between Objectives and
Outcomes?
Answer:
•Objectives set the targets for efforts; outcomes are the result
•Knowing the desired outcomes defines the objectives
•Initiating/implementing information security governance ■ first step in securing
information security program outcomes
•Understanding and clarifying outcomes or results provides both direction and
guidance for:
•Defining specific objectives
•Determining whether those outcomes are being achieved
Question:
What are the six outcomes of an effective information
security governance program?
Answer:
•Strategic alignment ■ Aligning security activities with business strategy to
support organizational objectives
•Risk management ■ Executing appropriate measures to manage risks and
potential impacts to an acceptable level
•Business process assurance/convergence ■ Integrating all relevant assurance
processes to maximize the effectiveness and efficiency of security activities
•Value delivery ■ Optimizing investments in support of business objectives
•Resource management ■ Using organizational resources efficiently and
effectively
•Performance measurement ■ Monitoring and reporting on security processes to
ensure that business objectives are achieved
Question:
What are the questions that must be asked in regards to
the six outcomes of an effective information security
,governance program?
Answer:
•How much alignment with organizational objectives must security have?
• How do we define and measure it?
• Is alignment increasing or decreasing?
• How can it be measured?
•What levels must risk be managed to:
•What measurement(s) determine(s) when it is achieved
•What options are available integrating assurance functions:
• How can the silo effect of safety efforts be countered
• What constitutes an optimal level of integration.
•What is an adequate or optimal level of value delivery:
• How can it be improved?
• How can it be measured?
•How do we determine if resources are being used effectively and efficiently?
•What level of performance measurement is sufficient in guiding the security
program and maintaining an acceptable level of security?
Question:
What is a common approach to create practical points of
reference to gauge the extent to which these outcomes
will be realized?
Answer:
•They create practical reference points gauging extent to which outcomes are
realized
•Goals developed in conjunction with the organization's business and operational
units ensures relevance to their activities
•They can be any form of metric, whether an actual numeric value such as the
number of complaints in some period of time or periodic surveys of
organizational sentiment regarding security
•They provide useful feedback for security management for navigating the
program and providing a general metric for monitoring organizational progress
Question:
What are the Key Goal Indicators (KGI) for Strategic
Alignment?
Answer:
•Lines of business have defined security requirements and control objectives
•Business requirements drive security initiatives
•Security activities do not materially hinder business
•Security program enables certain business activities
•Security activities provide predictable operations
•Security resources are allocated in proportion to business criticality
Question:
What are the Key Goal Indicators (KGI) for Risk
Management?
, Answer:
•Risk Assessment Completed
•Business Impact Assessments Performed or Completed
•Business Continuity Planning/Disaster Recovery (BCP/DR) Developed,
Implemented, Completed, or Tested
•Risk Appetite and Risk Tolerances Defined
•Asset Classification Performed, Initiated, or Completed
•Have an overall security strategy and program for achieving acceptable levels of
risk
•Define mitigation objectives for identified significant risks
•Have processes for management or reduction of adverse impacts
•Have systematic, continuous risk management processes
•Show trends of periodic risk assessment, indicating progress toward defined
goals
•Show trends in impacts
•Perform analysis of collective impact of aggregated risk
•Establish and show recognition for potential cascading impacts
Question:
What are the Key Goal Indicators (KGI) for Business
Process Assurance/Convergence?
Answer:
•Incidents, or a lack of them, traceable to a lack of integration
•The number of management levels before assurance processes fall under the
same organizational position
•Inconsistencies or contradictions in the objectives, policies, and standards
applied to various assurance functions
•An absence of communications between assurance providers
Question:
What are the Key Goal Indicators (KGI) for Value
Delivery?
Answer:
•Security activities are designed to achieve specific strategic objectives
•The cost of security being proportional to the value of assets
•Security resources are allocated by degree of assessed risk and potential impact
•Controls are based on defined control objectives and are fully used
•An adequate and appropriate number of controls to achieve acceptable risk and
impact levels
•Control effectiveness that is determined by periodic testing
•Policies in place that require all controls to be periodically reevaluated for cost,
compliance, reliability, and effectiveness
•Controls usage ■ controls that are rarely used are not likely to be cost-effective
•The number of controls to achieve acceptable risk and impact levels ■ fewer
effective controls can be expected to be more cost-effective than more less-
effective controls
Question:
UPDATED ACTUAL QUESTIONS AND CORRECT
ANSWERS
Question:
Define:
Gap Analysis
Information Security Framework
Answer:
Gap Analysis: It is a Technique for determining the steps to be taken in moving
from current state to desired future state.
Information Security Framework: Is a defined set of components used to design,
manage, and measure an information security program.
Question:
What is the difference between Objectives and
Outcomes?
Answer:
•Objectives set the targets for efforts; outcomes are the result
•Knowing the desired outcomes defines the objectives
•Initiating/implementing information security governance ■ first step in securing
information security program outcomes
•Understanding and clarifying outcomes or results provides both direction and
guidance for:
•Defining specific objectives
•Determining whether those outcomes are being achieved
Question:
What are the six outcomes of an effective information
security governance program?
Answer:
•Strategic alignment ■ Aligning security activities with business strategy to
support organizational objectives
•Risk management ■ Executing appropriate measures to manage risks and
potential impacts to an acceptable level
•Business process assurance/convergence ■ Integrating all relevant assurance
processes to maximize the effectiveness and efficiency of security activities
•Value delivery ■ Optimizing investments in support of business objectives
•Resource management ■ Using organizational resources efficiently and
effectively
•Performance measurement ■ Monitoring and reporting on security processes to
ensure that business objectives are achieved
Question:
What are the questions that must be asked in regards to
the six outcomes of an effective information security
,governance program?
Answer:
•How much alignment with organizational objectives must security have?
• How do we define and measure it?
• Is alignment increasing or decreasing?
• How can it be measured?
•What levels must risk be managed to:
•What measurement(s) determine(s) when it is achieved
•What options are available integrating assurance functions:
• How can the silo effect of safety efforts be countered
• What constitutes an optimal level of integration.
•What is an adequate or optimal level of value delivery:
• How can it be improved?
• How can it be measured?
•How do we determine if resources are being used effectively and efficiently?
•What level of performance measurement is sufficient in guiding the security
program and maintaining an acceptable level of security?
Question:
What is a common approach to create practical points of
reference to gauge the extent to which these outcomes
will be realized?
Answer:
•They create practical reference points gauging extent to which outcomes are
realized
•Goals developed in conjunction with the organization's business and operational
units ensures relevance to their activities
•They can be any form of metric, whether an actual numeric value such as the
number of complaints in some period of time or periodic surveys of
organizational sentiment regarding security
•They provide useful feedback for security management for navigating the
program and providing a general metric for monitoring organizational progress
Question:
What are the Key Goal Indicators (KGI) for Strategic
Alignment?
Answer:
•Lines of business have defined security requirements and control objectives
•Business requirements drive security initiatives
•Security activities do not materially hinder business
•Security program enables certain business activities
•Security activities provide predictable operations
•Security resources are allocated in proportion to business criticality
Question:
What are the Key Goal Indicators (KGI) for Risk
Management?
, Answer:
•Risk Assessment Completed
•Business Impact Assessments Performed or Completed
•Business Continuity Planning/Disaster Recovery (BCP/DR) Developed,
Implemented, Completed, or Tested
•Risk Appetite and Risk Tolerances Defined
•Asset Classification Performed, Initiated, or Completed
•Have an overall security strategy and program for achieving acceptable levels of
risk
•Define mitigation objectives for identified significant risks
•Have processes for management or reduction of adverse impacts
•Have systematic, continuous risk management processes
•Show trends of periodic risk assessment, indicating progress toward defined
goals
•Show trends in impacts
•Perform analysis of collective impact of aggregated risk
•Establish and show recognition for potential cascading impacts
Question:
What are the Key Goal Indicators (KGI) for Business
Process Assurance/Convergence?
Answer:
•Incidents, or a lack of them, traceable to a lack of integration
•The number of management levels before assurance processes fall under the
same organizational position
•Inconsistencies or contradictions in the objectives, policies, and standards
applied to various assurance functions
•An absence of communications between assurance providers
Question:
What are the Key Goal Indicators (KGI) for Value
Delivery?
Answer:
•Security activities are designed to achieve specific strategic objectives
•The cost of security being proportional to the value of assets
•Security resources are allocated by degree of assessed risk and potential impact
•Controls are based on defined control objectives and are fully used
•An adequate and appropriate number of controls to achieve acceptable risk and
impact levels
•Control effectiveness that is determined by periodic testing
•Policies in place that require all controls to be periodically reevaluated for cost,
compliance, reliability, and effectiveness
•Controls usage ■ controls that are rarely used are not likely to be cost-effective
•The number of controls to achieve acceptable risk and impact levels ■ fewer
effective controls can be expected to be more cost-effective than more less-
effective controls
Question: