Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Document preview thumbnail
Preview 2 out of 6 pages
Exam (elaborations)

Chapter 4: Security Management Question and answers correctly solved 2025/2026

Document preview thumbnail
Preview 2 out of 6 pages

Chapter 4: Security Management Question and answers correctly solved 2025/2026 What does security management entail? - correct answer Establishing, implementing, and monitoring an information security program, under the direction of a senior responsible person. Security management involves multiple levels of management and should be complementary so that each can help the others be more effective. What are the 2 roles security governance defines? - correct answer 1. CISO: - Has overall responsibility for the enterprise information security program. - Is the liaison between executive management and the information security program. - Should also communicate an

Content preview

Chapter 4: Security Management
Question and answers correctly
solved 2025/2026
What does security management entail? - correct answer ✔Establishing, implementing, and monitoring
an information security program, under the direction of a senior responsible person.



Security management involves multiple levels of management and should be complementary so that
each can help the others be more effective.



What are the 2 roles security governance defines? - correct answer ✔1. CISO:

- Has overall responsibility for the enterprise information security program.

- Is the liaison between executive management and the information security program.

- Should also communicate and coordinate closely with key business stakeholders to address
information protection needs.



2. Information Security Manager (ISM):

- Has responsibility for the management of information security efforts.



What is capital planning? - correct answer ✔A decision-making process for ensuring that IT investments
integrate strategic planning, budgeting, procurement, and the management of IT in support of an
organization's missions and business needs.



What are the 11 key security program areas in the NISTIR 7359, Information Security Guide for
Government Executives? - correct answer ✔1. Security planning.

2. Capital planning.

3. Awareness and training.

, 4. Information security governance.

5. System development life cycle.

6. Security products and services acquisition.

7. Risk management.

8. Configuration management.

9. Incident response.

10. Contingency planning.

11. Performance measures.



What is configuration management? - correct answer ✔The process of controlling modification to a
system's hardware, software, and documentation, which provides sufficient assurance that the system is
protected against the introduction of improper modification before, during, and after system
implementation.



Another useful source of guidance on the information management security function is the ISF SGP,
which recommends that this function encompass 5 CISO responsibilities. What are they? - correct
answer ✔1. Consistent organization-wide use of security.

2. Support function.

3. Monitor function.

4. Project functions.

5. External requirements function.



What is a security plan? - correct answer ✔A formal document that provides an overview of the
security requirements for an information system and describes the security controls in place or planned
for meeting those requirements.



What is the purpose of security planning within the NIST SP 800-18, Guide for Developing Security Plans
for Federal Information Systems? - correct answer ✔The purpose of a system security plan is to provide

Document information

Uploaded on
October 11, 2025
Number of pages
6
Written in
2025/2026
Type
Exam (elaborations)
Contains
Questions & answers
$14.99

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
STUVIAMAESTRO254
2.6
(40)
Sold
168
Followers
98
Items
9654
Last sold
1 month ago



Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions