Security Program Development & Management Flashcards
7 cards from real CCISO practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Security Program Development & Management flashcards as text
A CISO is asked to reduce the security budget by 20%. Which approach BEST demonstrates risk-informed decision-making?
Answer: Map proposed cuts to their risk impact and present the analysis to leadership
Mapping cuts to risk impact ensures leadership understands the consequences and makes an informed decision rather than the CISO absorbing the risk silently.
Which of the following BEST describes the concept of 'security by design' in program management?
Answer: Incorporating security requirements and controls into systems from their initial design phase
Security by design means embedding security considerations from the earliest stages of system design rather than adding them after development.
A CISO is implementing a security program for a recently acquired company. What is the MOST critical first step in integration?
Answer: Conducting a gap assessment comparing the acquired company's controls to parent company standards
A gap assessment reveals where the acquired company's security posture deviates from standards, enabling a risk-prioritized integration roadmap.
What is the PRIMARY benefit of implementing a formal exception management process within a security program?
Answer: It provides a documented, risk-accepted path for business units that cannot immediately comply with policy
Exception management balances business agility with risk governance by formally documenting, approving, and tracking deviations from security policy.
An organization's security program lacks integration with its enterprise risk management (ERM) framework. Which outcome is MOST likely?
Answer: Security risks will not be properly prioritized or reported alongside other enterprise risks
Without ERM integration, security risks are managed in isolation and may be under-resourced or misaligned with the organization's overall risk appetite.
A CISO wants to assess whether security controls are operating effectively, not just whether they exist. Which activity BEST accomplishes this?
Answer: Conducting control effectiveness testing through audits and red team exercises
Control effectiveness testing, including audits and adversarial simulations, validates that controls work as intended under real conditions.
Which metric BEST measures the effectiveness of a vulnerability management program within a security program?
Answer: Mean time to remediate (MTTR) critical vulnerabilities within defined SLA targets
MTTR against defined SLAs measures whether the program is actually closing risk in a timely manner, not just discovering vulnerabilities.