Latest Update.
When can executives be charged with negligence?
A. If they follow the transborder laws
B. If they do not properly report and prosecute attackers
C. If they properly inform users that they may be monitored
D. If they do not practice due care when protecting resources - Correct Answer D.
Executives are held to a certain standard and are expected to act responsibly when
running and protecting a company. These standards and expectations equate to the due
care concept under the law. Due care means to carry out activities that a reasonable
person would be expected to carry out in the same situation. If an executive acts
irresponsibly in any way, she can be seen as not practicing due care and be held
negligent.
To better deal with computer crime, several legislative bodies have taken what steps in
their strategy?
A. Expanded several privacy laws
B. Broadened the definition of property to include data
C. Required corporations to have computer crime insurance - Correct Answer B. Many
times, what is corrupted, compromised, or taken from a computer is data, so current laws
have been updated to include the protection of intangible assets, as in data. Over the
years, data and information have become many companies' most valuable asset, which
must be protected by the laws.
Which factor is the most important item when it comes to ensuring security is successful in
an organization?
A. Senior management support
,B. Effective controls and implementation methods
C. Updated and relevant security policies and procedures
D. Security awareness by all employees - Correct Answer A. Without senior
management's support, a security program will not receive the necessary attention, funds,
resources, and enforcement capabilities.
Which of the following standards would be most useful to you in ensuring your information
security management system follows industry best practices?
A. NIST SP 800-53
B. Six Sigma
C. ISO/IEC 27000 series
D. COSO IC - Correct Answer C. The ISO/IEC 27000 series is the only option that
addresses best practices across the breadth of an ISMS. COSO IC and NIST SP 800-53
both deal with controls, which are a critical but not the only component of an ISMS.
Which of the following is true about data breaches?
A. They are exceptionally rare.
B. They always involve personally identifiable information (PII).
C. They may trigger legal or regulatory requirements.
D. The United States has no laws pertaining to data breaches. - Correct Answer C.
Organizations experiencing a data breach may be required by laws or regulations to take
certain actions. For instance, many countries have disclosure requirements that require
notification to affected parties and/or regulatory bodies within a specific timeframe.
When is it acceptable to not take action on an identified risk?
, A. Never. Good security addresses and reduces all risks.
B. When political issues prevent this type of risk from being addressed.
C. When the necessary countermeasure is complex.
D. When the cost of the countermeasure outweighs the value of the asset and potential
loss. - Correct Answer D. Companies may decide to live with specific risks they are faced
with if the cost of trying to protect themselves would be greater than the potential loss if the
threat were to become real. Countermeasures are usually complex to a degree, and there
are almost always political issues surrounding different risks, but these are not reasons to
not implement a countermeasure.
Which is the most valuable technique when determining if a specific security control
should be implemented?
A. Risk analysis
B. Cost/benefit analysis
C. ALE results
D. Identifying the vulnerabilities and threats causing the risk - Correct Answer B. Although
the other answers may seem correct, B is the best answer here. This is because a risk
analysis is performed to identify risks and come up with suggested countermeasures. The
ALE tells the company how much it could lose if a specific threat became real. The ALE
value will go into the cost/benefit analysis, but the ALE does not address the cost of the
countermeasure and the benefit of a countermeasure. All the data captured in answers A,
C, and D is inserted into a cost/benefit analysis.
Which best describes the purpose of the ALE calculation?
A. Quantifies the security level of the environment
B. Estimates the loss possible for a countermeasure
C. Quantifies the cost/benefit result