← All CCISO Flashcard Decks

Information Security & Risk Management Flashcards

7 cards from real CCISO practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Information Security & Risk Management flashcards as text
  1. A CISO is implementing a risk-based security program. Which framework specifically integrates risk management into a continuous monitoring strategy for federal information systems?

    Answer: NIST RMF

    NIST Risk Management Framework (RMF) provides a disciplined, structured, and flexible process that integrates security and risk management into the system development life cycle for federal systems.

  2. When conducting a risk assessment, the term 'threat agent' most accurately refers to:

    Answer: An entity that initiates a threat event

    A threat agent is the actor or entity (person, organization, or natural event) that can exploit a vulnerability to cause harm to an asset.

  3. An organization's risk register shows a residual risk that exceeds the acceptable risk threshold. What is the MOST appropriate CISO action?

    Answer: Escalate to executive leadership for a risk acceptance decision

    When residual risk exceeds the acceptable threshold, the CISO must escalate to executive leadership who have the authority to formally accept or direct additional risk treatment.

  4. Which risk treatment option is applied when an organization decides to stop performing an activity that generates unacceptable risk?

    Answer: Risk avoidance

    Risk avoidance eliminates the risk by discontinuing the activity or process that creates the unacceptable exposure.

  5. A qualitative risk assessment differs from a quantitative risk assessment primarily because it:

    Answer: Relies on subjective ratings such as high, medium, and low

    Qualitative risk assessments use descriptive scales (high/medium/low) rather than numerical financial values, making them faster but more subjective than quantitative methods.

  6. In the context of information security governance, which of the following BEST describes the relationship between policies, standards, and procedures?

    Answer: Policies set direction; standards define requirements; procedures provide step-by-step instructions

    Policies establish high-level direction and intent, standards set specific mandatory requirements, and procedures provide detailed step-by-step instructions for implementation.

  7. An organization uses ALE (Annual Loss Expectancy) to prioritize security investments. ALE is calculated as:

    Answer: Single Loss Expectancy × Annualized Rate of Occurrence

    ALE = SLE × ARO, where Single Loss Expectancy is the financial loss per incident and Annualized Rate of Occurrence is how often the incident is expected per year.