Chapter3 Flashcards

1
Q

T/f
Because it sets out general business intentions, a mission statement does not need to be concise.

A

False

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

T/F
A clearly directed strategy flows from top to bottom rather than from bottom to top.

A

True

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

T/F
The primary goal of external monitoring is to maintain an informed awareness of the state of all of the organization’s networks, information systems, and information security defenses.

A

False

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

T/F
A top-down approach to information security usually begins with a systems administrator’s attempt to improve the security of their systems.

A

False

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

T/F
Penetration testing is often conducted by penetration testers—consultants or outsourced contractors who might be referred to as red teams.

A

True

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

T/F
Values statements should therefore be ambitous; after all, they are meant to express the aspirations of the organization.

A

False- Vision

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

T/F
A person or organization that has a vested interest in a particular aspect of the planning or operation of the organization is a stockbroker.

A

False- Stakeholder

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

T/F
The ISA 27014:2013 standard promotes five risk management processes, which should be adopted by the organization’s executive management and its governing board.

A

False- Governance

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

T/F
Enterprise risk management is a valuable approach that can better align security functions with the business mission while offering opportunities to lower costs.

A

True

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Which of the following explicitly declares the business of the organization and its intended areas of operations? a. vision statement b. values statement c. mission statement d. business statement

A

C- mission

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Which type of planning is the primary tool in determining the long-term direction taken by an organization? a. strategic b. tactical c. operational d. managerial

A

A- strategic

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Which of the following is true about planning? a. Strategic plans are used to create tactical plans b. Tactical plans are used to create strategic plans c. Operational plans are used to create tactical plans d. Operational plans are used to create strategic plans

A

A- Stragetic plans are use to create tactical plans

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Which level of planning breaks down each applicable strategic goal into a series of incremental objectives? a. strategic b. operational c. organizational d. tactical

A

D- tactical

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Which type of planning is used to organize the ongoing, day-to-day performance of tasks? a. Strategic b. Tactical c. Organizational d. Operational

A

D- Operational

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

The basic outcomes of InfoSec governance should include all but which of the following? a. Value delivery by optimizing InfoSec investments in support of organizational objectives b. Performance measurement by measuring, monitoring, and reporting information security governance metrics to ensure that organizational objectives are achieved c. Time management by aligning resources with personnel schedules and organizational objectives d. Resource management by utilizing information security knowledge and infrastructure efficiently and effectively

A

C

How well did you know this?
1
Not at all
2
3
4
5
Perfectly