Question and answers correctly
solved 2025/2026
What does security management entail? - correct answer ✔Establishing, implementing, and monitoring
an information security program, under the direction of a senior responsible person.
Security management involves multiple levels of management and should be complementary so that
each can help the others be more effective.
What are the 2 roles security governance defines? - correct answer ✔1. CISO:
- Has overall responsibility for the enterprise information security program.
- Is the liaison between executive management and the information security program.
- Should also communicate and coordinate closely with key business stakeholders to address
information protection needs.
2. Information Security Manager (ISM):
- Has responsibility for the management of information security efforts.
What is capital planning? - correct answer ✔A decision-making process for ensuring that IT investments
integrate strategic planning, budgeting, procurement, and the management of IT in support of an
organization's missions and business needs.
What are the 11 key security program areas in the NISTIR 7359, Information Security Guide for
Government Executives? - correct answer ✔1. Security planning.
2. Capital planning.
3. Awareness and training.
, 4. Information security governance.
5. System development life cycle.
6. Security products and services acquisition.
7. Risk management.
8. Configuration management.
9. Incident response.
10. Contingency planning.
11. Performance measures.
What is configuration management? - correct answer ✔The process of controlling modification to a
system's hardware, software, and documentation, which provides sufficient assurance that the system is
protected against the introduction of improper modification before, during, and after system
implementation.
Another useful source of guidance on the information management security function is the ISF SGP,
which recommends that this function encompass 5 CISO responsibilities. What are they? - correct
answer ✔1. Consistent organization-wide use of security.
2. Support function.
3. Monitor function.
4. Project functions.
5. External requirements function.
What is a security plan? - correct answer ✔A formal document that provides an overview of the
security requirements for an information system and describes the security controls in place or planned
for meeting those requirements.
What is the purpose of security planning within the NIST SP 800-18, Guide for Developing Security Plans
for Federal Information Systems? - correct answer ✔The purpose of a system security plan is to provide