INMT 341 Final Exam Questions and
Answers
Average breech cost - Answer-3.8mm global, 8.6mm USA, $242/record
Capital One Breech - Answer--credit card information stolen b/c amazon services which gave more
internal info than should have - misconfiguration
Equifax Breech - Answer-credit info, stolen b/c vulnerability was known and they didn't update their
systems - 1.14 billion to 1.8 billion
GRC - Answer-- Governance, Risk, Compliance
- structured approach to aligning IT with business objectives and managing risk and meeting compliance
requirements
Governance - Answer--Ensuring organizational activities are aligned in a way that supports business
goals
-someone is responsible
-framework
Governance vs Management - Answer--management is boots on the ground and governance is BOD
-management performs the operations and governance oversees management
, -responsibility of shareholders and executive management
-implemented/accomplished throughout organization
Risk - Answer--what can go wrong
-
ITIL - Answer--governance framework
-international standard
-wheel with service strategy in the middle and continual process improvement on outside
ISO/IEC 38500:20015 - Answer--specific to USA
-can follow w/ or w/out getting certified
-purpose to promote effective, efficient and acceptable use of UT in an organization
COBIT - Answer--framework
-comprehensive
-see what risks are a possibility and then follow the rules to mitigate that risk
Compliance - Answer--depends on what info you have to determine what the regulations are
-comply with various regulations
PCI-DSS - Answer--anywhere that accepts credit cards must comply with this - standard that protects
credit information
FERPA - Answer--family educational rights and privacy act
-school information
Answers
Average breech cost - Answer-3.8mm global, 8.6mm USA, $242/record
Capital One Breech - Answer--credit card information stolen b/c amazon services which gave more
internal info than should have - misconfiguration
Equifax Breech - Answer-credit info, stolen b/c vulnerability was known and they didn't update their
systems - 1.14 billion to 1.8 billion
GRC - Answer-- Governance, Risk, Compliance
- structured approach to aligning IT with business objectives and managing risk and meeting compliance
requirements
Governance - Answer--Ensuring organizational activities are aligned in a way that supports business
goals
-someone is responsible
-framework
Governance vs Management - Answer--management is boots on the ground and governance is BOD
-management performs the operations and governance oversees management
, -responsibility of shareholders and executive management
-implemented/accomplished throughout organization
Risk - Answer--what can go wrong
-
ITIL - Answer--governance framework
-international standard
-wheel with service strategy in the middle and continual process improvement on outside
ISO/IEC 38500:20015 - Answer--specific to USA
-can follow w/ or w/out getting certified
-purpose to promote effective, efficient and acceptable use of UT in an organization
COBIT - Answer--framework
-comprehensive
-see what risks are a possibility and then follow the rules to mitigate that risk
Compliance - Answer--depends on what info you have to determine what the regulations are
-comply with various regulations
PCI-DSS - Answer--anywhere that accepts credit cards must comply with this - standard that protects
credit information
FERPA - Answer--family educational rights and privacy act
-school information