Security Management Practices Quiz 1
questions and answers graded A+
Information Security - correct answer ✔✔ Ensures that within the enterprise, information is
protected against disclosure to unauthorized users (confidentiality), improper modification
(integrity), and non-access when required (availability).
Information Technology Security - correct answer ✔✔ Is the process of implementing measures
and systems designed to securely protect and safeguard information (business and person data,
voice conversations, still images, motion pictures, multimedia presentations, including those not
yet conceived) utilizing various forms of technology developed to create, store, use and
exchange such information against any unauthorized access, misuse, malfunction, modification,
destruction, or improper disclosure, thereby preserving the value, confidentiality, integrity,
availability, intended use and its ability to perform their permitted critical functions.
Cyber Security - correct answer ✔✔ The protection of information assets by addressing threats
to information processed, stored, and transported by internetworked information systems.
Cyberspace - correct answer ✔✔ A global domain within the information environment
consisting of the interdependent network of information systems infrastructures including the
internet, telecommunications networks, computer systems, and embedded processors and
controllers.
Governance - correct answer ✔✔ The act of manner of governing, of exercising control or
authority over the actions of subjects; a system of regulations.
Information Governance - correct answer ✔✔ Specification of decision rights and an
accountability framework ensuring appropriate behavior in the valuation, creation, storage, use,
archiving and deletion of information. It includes the processes, roles and policies, standards
,and metrics that ensure the effective and efficient use of information in enabling an
organization to achieve its goals.
Segregation/Separation of Duties - correct answer ✔✔ A basic internal control that prevents or
detects errors and irregularities by assigning to separate individuals the responsibility for
initiating and recording transactions and for the custody of assets.
Toxic Combinations - correct answer ✔✔ A situation where a user has a combination of
entitlements/access on the system (or combination of systems), that gives them the ability to
perform tasks that should never be controlled by a single user.
What is the difference between data and information? - correct answer ✔✔ Data is raw,
unorganized facts that need to be processed. Data can be something simple and seemingly
random and useless until it is organized. When data is processed, organized, structured or
presented in a given context so as to make it useful, it is called information.
At what layer in the Open System Interconnect (OSI) Module does data become information? -
correct answer ✔✔ Layer 7 - Application Layer
What are the different stages of information within its lifecycle? - correct answer ✔✔ Generate;
Process; Update; Re-Use; Store; Delete
What are two takeaways as information value decrease over time? - correct answer ✔✔ •The
Information Technology management cost remains constant, with a widening gap as costs
exceed value over time
• e-discovery risk increases as information ages and context is lost, creating an even larger gap
as value declines and risk increases
What are the Key Terms according Gartner in regards to Information Governance? - correct
answer ✔✔ The Key Terms
,•Accountability framework for information
•Processes, roles, standards, metrics
•Effective, efficient use of information to achieve goals
What are some of the failures of not implementing an effective Information Security
Governance Program? - correct answer ✔✔ •Continued chaotic, increasingly expensive, and
marginally effective firefighting mode of operation
•
•Continued deployment of Tactical point solutions
•
•Continued fragmentation of "assurance-" and security-related stovepipes
•
•Continued haphazard security resources allocations that are unrelated to risks and impacts as
well as to cost-effectiveness
Failure of not Implementing an Effective Information Security Governance Program (Continued)
- correct answer ✔✔ •Incidents, breaches and losses continuously grows
•Regulatory compliance becoming more costly
•Senior management responsible; legally liable for failing the requirements of due care and
diligence
•Customers demand greater care and, failing to get it, will vote with their feet
•The correlation between security, customer satisfaction, and business success is become
increasingly obvious and reflected in share value
Define Operational, Tactical and Strategic Planning Process - correct answer ✔✔ Strategic:
•Long-term (3-5 year) direction considers organizational goals, regulation (and for IT: technical
advances)
•Another view: Anything greater than 1 year in duration
, Tactical: 1-year plan moves organization to strategic goal
Operational: Detailed or technical plans, at most 3 to 6 months outlook
Strategic Planning - correct answer ✔✔ •Process of defining an organization's strategy, or
direction, and making decisions on allocating its resources to pursue this strategy
•Deals, on the whole business, rather than just an isolated unit
•Looks at 3 to 5 years, although some extend their vision to 20 years (long term)
•Asks at least one of following three key questions:
•"What do we do?"
•"For whom do we do it?"
•"How do we excel?"
•Deal with significant uncertainties
•Addresses "strategic risks"
Tactical Planning - correct answer ✔✔ •Short range planning emphasizing current operations of
various parts of the organization
•Generally defined as a period of time extending about one year or less in the future
•Outlines what various parts of the organization must do for the organization to be successful at
some point one year or less into the future
•Deals with moderate uncertainties that lie closer to the control of management than strategic
ones
•Addresses "tactical risks"
Operational Planning - correct answer ✔✔ •Process of linking strategic goals and objectives to
tactical goals and objectives
•Generally 3 to 6 months in duration at most
•Describes milestones, conditions for success and explains how, or what portion of, a strategic
plan will be put into operation during a given operational period.
questions and answers graded A+
Information Security - correct answer ✔✔ Ensures that within the enterprise, information is
protected against disclosure to unauthorized users (confidentiality), improper modification
(integrity), and non-access when required (availability).
Information Technology Security - correct answer ✔✔ Is the process of implementing measures
and systems designed to securely protect and safeguard information (business and person data,
voice conversations, still images, motion pictures, multimedia presentations, including those not
yet conceived) utilizing various forms of technology developed to create, store, use and
exchange such information against any unauthorized access, misuse, malfunction, modification,
destruction, or improper disclosure, thereby preserving the value, confidentiality, integrity,
availability, intended use and its ability to perform their permitted critical functions.
Cyber Security - correct answer ✔✔ The protection of information assets by addressing threats
to information processed, stored, and transported by internetworked information systems.
Cyberspace - correct answer ✔✔ A global domain within the information environment
consisting of the interdependent network of information systems infrastructures including the
internet, telecommunications networks, computer systems, and embedded processors and
controllers.
Governance - correct answer ✔✔ The act of manner of governing, of exercising control or
authority over the actions of subjects; a system of regulations.
Information Governance - correct answer ✔✔ Specification of decision rights and an
accountability framework ensuring appropriate behavior in the valuation, creation, storage, use,
archiving and deletion of information. It includes the processes, roles and policies, standards
,and metrics that ensure the effective and efficient use of information in enabling an
organization to achieve its goals.
Segregation/Separation of Duties - correct answer ✔✔ A basic internal control that prevents or
detects errors and irregularities by assigning to separate individuals the responsibility for
initiating and recording transactions and for the custody of assets.
Toxic Combinations - correct answer ✔✔ A situation where a user has a combination of
entitlements/access on the system (or combination of systems), that gives them the ability to
perform tasks that should never be controlled by a single user.
What is the difference between data and information? - correct answer ✔✔ Data is raw,
unorganized facts that need to be processed. Data can be something simple and seemingly
random and useless until it is organized. When data is processed, organized, structured or
presented in a given context so as to make it useful, it is called information.
At what layer in the Open System Interconnect (OSI) Module does data become information? -
correct answer ✔✔ Layer 7 - Application Layer
What are the different stages of information within its lifecycle? - correct answer ✔✔ Generate;
Process; Update; Re-Use; Store; Delete
What are two takeaways as information value decrease over time? - correct answer ✔✔ •The
Information Technology management cost remains constant, with a widening gap as costs
exceed value over time
• e-discovery risk increases as information ages and context is lost, creating an even larger gap
as value declines and risk increases
What are the Key Terms according Gartner in regards to Information Governance? - correct
answer ✔✔ The Key Terms
,•Accountability framework for information
•Processes, roles, standards, metrics
•Effective, efficient use of information to achieve goals
What are some of the failures of not implementing an effective Information Security
Governance Program? - correct answer ✔✔ •Continued chaotic, increasingly expensive, and
marginally effective firefighting mode of operation
•
•Continued deployment of Tactical point solutions
•
•Continued fragmentation of "assurance-" and security-related stovepipes
•
•Continued haphazard security resources allocations that are unrelated to risks and impacts as
well as to cost-effectiveness
Failure of not Implementing an Effective Information Security Governance Program (Continued)
- correct answer ✔✔ •Incidents, breaches and losses continuously grows
•Regulatory compliance becoming more costly
•Senior management responsible; legally liable for failing the requirements of due care and
diligence
•Customers demand greater care and, failing to get it, will vote with their feet
•The correlation between security, customer satisfaction, and business success is become
increasingly obvious and reflected in share value
Define Operational, Tactical and Strategic Planning Process - correct answer ✔✔ Strategic:
•Long-term (3-5 year) direction considers organizational goals, regulation (and for IT: technical
advances)
•Another view: Anything greater than 1 year in duration
, Tactical: 1-year plan moves organization to strategic goal
Operational: Detailed or technical plans, at most 3 to 6 months outlook
Strategic Planning - correct answer ✔✔ •Process of defining an organization's strategy, or
direction, and making decisions on allocating its resources to pursue this strategy
•Deals, on the whole business, rather than just an isolated unit
•Looks at 3 to 5 years, although some extend their vision to 20 years (long term)
•Asks at least one of following three key questions:
•"What do we do?"
•"For whom do we do it?"
•"How do we excel?"
•Deal with significant uncertainties
•Addresses "strategic risks"
Tactical Planning - correct answer ✔✔ •Short range planning emphasizing current operations of
various parts of the organization
•Generally defined as a period of time extending about one year or less in the future
•Outlines what various parts of the organization must do for the organization to be successful at
some point one year or less into the future
•Deals with moderate uncertainties that lie closer to the control of management than strategic
ones
•Addresses "tactical risks"
Operational Planning - correct answer ✔✔ •Process of linking strategic goals and objectives to
tactical goals and objectives
•Generally 3 to 6 months in duration at most
•Describes milestones, conditions for success and explains how, or what portion of, a strategic
plan will be put into operation during a given operational period.