What is the first step in applying the RMF? correct answers Categorize the information system and the
information processed
All of the following are risk treatments in different frameworks except? correct answers Ignore
Which of the following is NOT one of the components of the COSO framework? correct answers
Meeting stakeholder needs
Which of the following is a generic blueprint offered by a service organization which must be flexible,
scalable, robust, and detailed? correct answers security model, framework
The ISO 27005 Standard for InfoSec Risk Management includes a five-stage management methodology;
among them are risk treatment and risk communication. correct answers True
In information security, a framework or security model customized to an organization, including
implementation details is known as a floor plan. correct answers False
The Microsoft Risk Management Approach includes four phases. Which of the following is NOT one of
them? correct answers evaluating alternative strategies
The COSO framework is built on eight interrelated components. Which of the following is NOT one of
them? correct answers InfoSec Governance
Security risk decision variables include all the following aspects EXCEPT correct answers Weakness of
the security
OCTAVE is one of the many frameworks available. Although heavy and labor intensive, it includes
innovative approaches. One of the unique aspects of OCTAVE is the pools of mitigation approaches. The
pools used include everything but? correct answers Transfer
Which of the following is NOT a step in the FAIR risk management framework? correct answers Assess
and control impact