Ethics, and Privacy – Final Question
and answers rated A+ 2025/2026
True - correct answer ✔Since the responsibility for IT security is shared across the organization, there is
a risk of inconsistent implementation of security and a loss of central monitoring and control.
True - correct answer ✔It is likely that an organization will not have the resources to implement all the
recommended controls.
False - correct answer ✔The IT security management process ends with the implementation of controls
and the training of personnel.
True - correct answer ✔The relative lack of success in bringing cybercriminals to justice has led to an
increase in their numbers, boldness, and the global scale of their operations.
True - correct answer ✔The purpose of the privacy functions is to provide a user protection against
discovery and misuse of identity by other users.
risks, recommended controls, and responsible personnel - correct answer ✔An IT security plan should
include details of __________.
Anonymization - correct answer ✔_________ is a function that removes specific identifying
information from query results, such as last name and telephone number, but creates some sort of
unique identifier so that analysts can detect connections between queries.
T - correct answer ✔1. IT security management consists of first determining a clear view of an
organization's IT security objectives and general risk profile.
, T - correct answer ✔2. IT security management has evolved considerably over the last few decades due
to the rise in risks to networked systems.
F - correct answer ✔3. Detecting and reacting to incidents is not a function of IT security management.
T - correct answer ✔4. IT security needs to be a key part of an organization's overall management plan.
F - correct answer ✔5. Once the IT management process is in place and working the process never
needs to be repeated.
T - correct answer ✔6. Organizational security objectives identify what IT security outcomes should be
achieved.
F - correct answer ✔7. The assignment of responsibilities relating to the management of IT security and
the organizational infrastructure is not addressed in a corporate security policy.
T - correct answer ✔8. Organizational security policies identify what needs to be done.
F - correct answer ✔9. It is not critical that an organization's IT security policy have full approval or buy-
in by senior management.
T - correct answer ✔10. Because the responsibility for IT security is shared across the organization,
there is a risk of inconsistent implementation of security and a loss of central monitoring and control.
T - correct answer ✔11. Legal and regulatory constraints may require specific approaches to risk
assessment.