Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Document preview thumbnail
Preview 3 out of 22 pages
Exam (elaborations)

SECURITY MANAGEMENT PRACTICES EXAM THREE UPDATED ACTUAL QUESTIONS AND CORRECT ANSWERS

Document preview thumbnail
Preview 3 out of 22 pages

SECURITY MANAGEMENT PRACTICES EXAM THREE UPDATED ACTUAL QUESTIONS AND CORRECT ANSWERS

Content preview

SECURITY MANAGEMENT PRACTICES EXAM THREE
UPDATED ACTUAL QUESTIONS AND CORRECT
ANSWERS
Question:
Define:
Gap Analysis
Information Security Framework
Answer:
Gap Analysis: It is a Technique for determining the steps to be taken in moving
from current state to desired future state.
Information Security Framework: Is a defined set of components used to design,
manage, and measure an information security program.

Question:
What is the difference between Objectives and
Outcomes?
Answer:
•Objectives set the targets for efforts; outcomes are the result
•Knowing the desired outcomes defines the objectives
•Initiating/implementing information security governance ■ first step in securing
information security program outcomes
•Understanding and clarifying outcomes or results provides both direction and
guidance for:
•Defining specific objectives
•Determining whether those outcomes are being achieved

Question:
What are the six outcomes of an effective information
security governance program?
Answer:
•Strategic alignment ■ Aligning security activities with business strategy to
support organizational objectives
•Risk management ■ Executing appropriate measures to manage risks and
potential impacts to an acceptable level
•Business process assurance/convergence ■ Integrating all relevant assurance
processes to maximize the effectiveness and efficiency of security activities
•Value delivery ■ Optimizing investments in support of business objectives
•Resource management ■ Using organizational resources efficiently and
effectively
•Performance measurement ■ Monitoring and reporting on security processes to
ensure that business objectives are achieved

Question:
What are the questions that must be asked in regards to
the six outcomes of an effective information security

,governance program?
Answer:
•How much alignment with organizational objectives must security have?
• How do we define and measure it?
• Is alignment increasing or decreasing?
• How can it be measured?
•What levels must risk be managed to:
•What measurement(s) determine(s) when it is achieved
•What options are available integrating assurance functions:
• How can the silo effect of safety efforts be countered
• What constitutes an optimal level of integration.
•What is an adequate or optimal level of value delivery:
• How can it be improved?
• How can it be measured?
•How do we determine if resources are being used effectively and efficiently?
•What level of performance measurement is sufficient in guiding the security
program and maintaining an acceptable level of security?

Question:
What is a common approach to create practical points of
reference to gauge the extent to which these outcomes
will be realized?
Answer:
•They create practical reference points gauging extent to which outcomes are
realized
•Goals developed in conjunction with the organization's business and operational
units ensures relevance to their activities
•They can be any form of metric, whether an actual numeric value such as the
number of complaints in some period of time or periodic surveys of
organizational sentiment regarding security
•They provide useful feedback for security management for navigating the
program and providing a general metric for monitoring organizational progress

Question:
What are the Key Goal Indicators (KGI) for Strategic
Alignment?
Answer:
•Lines of business have defined security requirements and control objectives
•Business requirements drive security initiatives
•Security activities do not materially hinder business
•Security program enables certain business activities
•Security activities provide predictable operations
•Security resources are allocated in proportion to business criticality

Question:
What are the Key Goal Indicators (KGI) for Risk
Management?

, Answer:
•Risk Assessment Completed
•Business Impact Assessments Performed or Completed
•Business Continuity Planning/Disaster Recovery (BCP/DR) Developed,
Implemented, Completed, or Tested
•Risk Appetite and Risk Tolerances Defined
•Asset Classification Performed, Initiated, or Completed
•Have an overall security strategy and program for achieving acceptable levels of
risk
•Define mitigation objectives for identified significant risks
•Have processes for management or reduction of adverse impacts
•Have systematic, continuous risk management processes
•Show trends of periodic risk assessment, indicating progress toward defined
goals
•Show trends in impacts
•Perform analysis of collective impact of aggregated risk
•Establish and show recognition for potential cascading impacts

Question:
What are the Key Goal Indicators (KGI) for Business
Process Assurance/Convergence?
Answer:
•Incidents, or a lack of them, traceable to a lack of integration
•The number of management levels before assurance processes fall under the
same organizational position
•Inconsistencies or contradictions in the objectives, policies, and standards
applied to various assurance functions
•An absence of communications between assurance providers

Question:
What are the Key Goal Indicators (KGI) for Value
Delivery?
Answer:
•Security activities are designed to achieve specific strategic objectives
•The cost of security being proportional to the value of assets
•Security resources are allocated by degree of assessed risk and potential impact
•Controls are based on defined control objectives and are fully used
•An adequate and appropriate number of controls to achieve acceptable risk and
impact levels
•Control effectiveness that is determined by periodic testing
•Policies in place that require all controls to be periodically reevaluated for cost,
compliance, reliability, and effectiveness
•Controls usage ■ controls that are rarely used are not likely to be cost-effective
•The number of controls to achieve acceptable risk and impact levels ■ fewer
effective controls can be expected to be more cost-effective than more less-
effective controls

Question:

Document information

Uploaded on
August 30, 2026
Number of pages
22
Written in
2026/2027
Type
Exam (elaborations)
Contains
Questions & answers
$17.99

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
Briwisescore
3.0
(1)
Sold
27
Followers
5
Items
12364
Last sold
21 hours ago



Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions