CC Security Governance 2 — Questions and Answers
Question 1: Which metric best measures Security Governance effectiveness?
- Domain-specific KPIs aligned with defined objectives (Correct answer)
- Number of meetings held about the topic
- Amount of documentation produced
- Budget spent on related tools
Correct answer: Domain-specific KPIs aligned with defined objectives
Effectiveness of Security Governance is best measured through KPIs that align with defined objectives.
Question 2: How does Security Governance handle change management?
- Through controlled processes that assess impact before changes (Correct answer)
- Changes are not allowed once implemented
- All changes happen immediately without review
- Change management is handled separately
Correct answer: Through controlled processes that assess impact before changes
Changes to Security Governance should follow controlled processes with proper impact assessment.
Question 3: What documentation is essential for Security Governance?
- Policies, procedures, guidelines, and records of decisions (Correct answer)
- No documentation is needed
- Only a one-page summary document
- Only informal email notes
Correct answer: Policies, procedures, guidelines, and records of decisions
Essential Security Governance documentation includes policies, procedures, guidelines, and decision records.
Question 4: How does Security Governance contribute to continuous improvement?
- Through regular assessment, feedback loops, and iterative enhancement (Correct answer)
- By maintaining the status quo indefinitely
- By preventing any changes to existing processes
- Through one-time implementation only
Correct answer: Through regular assessment, feedback loops, and iterative enhancement
Continuous improvement in Security Governance comes from regular assessment and iterative enhancement cycles.
Question 5: What is the relationship between Security Governance and security?
- Security Governance includes security considerations as an integral component (Correct answer)
- Security is completely unrelated to this topic
- Security Governance replaces all other security measures
- Security only applies to network-related topics
Correct answer: Security Governance includes security considerations as an integral component
Security is an integral part of Security Governance, ensuring that implementations are protected and compliant.
Question 6: How should Security Governance be prioritized against competing organizational needs?
- Based on risk assessment and business impact analysis (Correct answer)
- Always given highest priority over everything else
- Always given lowest priority
- Prioritized randomly without analysis
Correct answer: Based on risk assessment and business impact analysis
Prioritization of Security Governance should be based on risk assessment and business impact.
Which metric best measures Security Governance effectiveness?