โ† All CCISO Flashcard Decks

Information Security & Risk Management Flashcards

7 cards from real CCISO practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Information Security & Risk Management flashcards as text
  1. An organization is implementing security metrics. Which characteristic is MOST important for a metric to be useful for security management decisions?

    Answer: The metric should be actionable and tied to a specific decision or outcome

    Effective security metrics must be actionable, meaning they provide information that can drive a specific management decision or corrective action.

  2. A CISO notices that control effectiveness reviews are only performed annually. What is the PRIMARY risk of infrequent control assessments?

    Answer: Controls may become ineffective due to environmental changes without detection

    Infrequent control assessments create a window where controls degraded by system changes, personnel turnover, or new threats go undetected, increasing residual risk.

  3. Which of the following BEST describes the 'defense in depth' principle as applied to information security risk management?

    Answer: Layering multiple independent controls so that failure of one does not compromise security

    Defense in depth implements multiple overlapping layers of controls so that if one control fails or is bypassed, additional controls continue to provide protection.

  4. Under the NIST Cybersecurity Framework (CSF), which function focuses on developing and implementing appropriate activities to identify cybersecurity risks?

    Answer: Identify

    The Identify function of the NIST CSF develops organizational understanding of managing cybersecurity risk to systems, assets, data, and capabilities.

  5. A CISO is evaluating whether to implement a new security control. The cost of the control is $50,000 annually and the ALE before the control is $120,000. The ALE after the control is $40,000. What is the value of implementing the control?

    Answer: $30,000 net benefit

    The control saves $80,000 (ALE reduction from $120K to $40K) but costs $50,000, yielding a net benefit of $30,000 annually.

  6. Which of the following is an example of a leading indicator in security risk management?

    Answer: Percentage of critical vulnerabilities unpatched beyond SLA

    Unpatched vulnerabilities beyond SLA is a leading indicator because it signals increased future risk before a breach occurs, unlike lagging indicators that measure past events.

  7. When developing a risk treatment plan, which element is ESSENTIAL to include to ensure accountability and track progress?

    Answer: Named ownership, target completion dates, and success criteria for each action

    A risk treatment plan must assign clear ownership, deadlines, and measurable success criteria so that progress can be tracked and accountability maintained.