CCISO Governance, Risk & Compliance 2 — Questions and Answers
Question 1: Which risk treatment option involves transferring the financial impact of a risk to a third party?
- Risk avoidance
- Risk mitigation
- Risk transference (Correct answer)
- Risk acceptance
Correct answer: Risk transference
Risk transference shifts the financial burden of a risk to another party, such as through cyber insurance or outsourcing.
Question 2: A CISO needs to align the security program with business objectives. Which framework is MOST appropriate for mapping security controls to business goals?
- COBIT 2019 (Correct answer)
- PCI DSS
- HIPAA Security Rule
- ISO 27001 Annex A
Correct answer: COBIT 2019
COBIT 2019 is specifically designed to align IT governance, including security, with overall enterprise business objectives.
Question 3: Under GDPR, what is the maximum time frame for reporting a personal data breach to the supervisory authority after becoming aware of it?
- 24 hours
- 48 hours
- 72 hours (Correct answer)
- 96 hours
Correct answer: 72 hours
GDPR Article 33 requires notification to the supervisory authority within 72 hours of becoming aware of a personal data breach.
Question 4: Which of the following BEST describes the purpose of a Statement of Applicability (SoA) in ISO 27001?
- Documents the organization's risk appetite
- Lists applicable controls and justifies inclusions and exclusions (Correct answer)
- Defines the scope of the ISMS boundary
- Outlines the business continuity plan
Correct answer: Lists applicable controls and justifies inclusions and exclusions
The SoA documents which Annex A controls are applicable, their implementation status, and the justification for including or excluding each control.
Question 5: A company operates in multiple jurisdictions with conflicting privacy laws. What is the BEST governance approach to address this?
- Apply the least restrictive law globally to minimize overhead
- Implement controls that satisfy the most stringent applicable regulation (Correct answer)
- Seek legal exemptions from conflicting requirements
- Operate under the laws of the corporate headquarters only
Correct answer: Implement controls that satisfy the most stringent applicable regulation
Implementing the most stringent applicable controls ensures compliance across all jurisdictions while minimizing legal risk.
Question 6: Which metric BEST helps a CISO demonstrate the business value of a security program to the board?
- Number of vulnerabilities patched per quarter
- Percentage of systems with antivirus installed
- Return on Security Investment (ROSI) (Correct answer)
- Mean time to detect (MTTD) in hours
Correct answer: Return on Security Investment (ROSI)
ROSI translates security investments into financial terms that resonate with business leadership, demonstrating cost-benefit value.
Question 7: What is the PRIMARY purpose of a security steering committee in an enterprise?
- To perform hands-on security testing
- To provide executive oversight and strategic direction for the security program (Correct answer)
- To manage day-to-day incident response
- To approve all firewall rule changes
Correct answer: To provide executive oversight and strategic direction for the security program
A security steering committee provides cross-functional executive governance, ensuring the security program aligns with business strategy.
Which risk treatment option involves transferring the financial impact of a risk to a third party?