CCISO Governance, Risk & Compliance 3 — Questions and Answers
Question 1: Which element distinguishes a risk register from a risk assessment report?
- The risk register is a one-time snapshot; the report is continuously updated
- The risk register is a living document tracking risks over time; the report captures a point-in-time analysis (Correct answer)
- The risk register contains only residual risks; the report contains inherent risks
- The risk register is produced by auditors; the report is produced by the security team
Correct answer: The risk register is a living document tracking risks over time; the report captures a point-in-time analysis
A risk register is a continuously maintained inventory of identified risks, while a risk assessment report captures risk findings at a specific point in time.
Question 2: An organization wants to adopt a risk-based approach to compliance. Which concept BEST supports this?
- Implementing every control in every applicable framework
- Prioritizing controls based on the likelihood and impact of associated risks (Correct answer)
- Achieving certification before addressing residual risks
- Delegating all compliance decisions to the legal department
Correct answer: Prioritizing controls based on the likelihood and impact of associated risks
A risk-based compliance approach focuses resources on controls that address the highest-likelihood and highest-impact risks first.
Question 3: Which type of policy establishes the organization's overall intention and direction for information security?
- Acceptable Use Policy
- Data Classification Policy
- Information Security Policy (Correct answer)
- Incident Response Policy
Correct answer: Information Security Policy
An Information Security Policy is the top-level document that sets the organization's strategic intent and commitment to protecting information assets.
Question 4: A third-party vendor will process sensitive customer data. Which contractual mechanism BEST ensures compliance with data protection requirements?
- Non-Disclosure Agreement (NDA)
- Data Processing Agreement (DPA) (Correct answer)
- Master Service Agreement (MSA)
- Service Level Agreement (SLA)
Correct answer: Data Processing Agreement (DPA)
A Data Processing Agreement legally defines how a third party must handle personal data and is required under regulations like GDPR.
Question 5: What is the key difference between qualitative and quantitative risk analysis?
- Qualitative analysis uses numerical financial values; quantitative uses descriptive ratings
- Qualitative uses descriptive categories like High/Medium/Low; quantitative uses numerical financial metrics like ALE (Correct answer)
- Qualitative is more accurate because it uses expert judgment
- Quantitative analysis is always preferred because it eliminates subjectivity
Correct answer: Qualitative uses descriptive categories like High/Medium/Low; quantitative uses numerical financial metrics like ALE
Qualitative analysis rates risks using descriptive scales, while quantitative analysis expresses risk in monetary terms such as Annual Loss Expectancy (ALE).
Question 6: Which regulation primarily governs the handling of protected health information (PHI) by healthcare organizations in the United States?
- GLBA
- SOX
- HIPAA (Correct answer)
- FERPA
Correct answer: HIPAA
HIPAA (Health Insurance Portability and Accountability Act) establishes privacy and security requirements for protected health information in the US.
Question 7: In the context of enterprise risk management, what does 'risk appetite' define?
- The maximum loss an organization can absorb before becoming insolvent
- The amount of risk an organization is willing to accept in pursuit of its objectives (Correct answer)
- The residual risk remaining after all controls are applied
- The probability threshold above which all risks must be mitigated
Correct answer: The amount of risk an organization is willing to accept in pursuit of its objectives
Risk appetite represents the board-level decision about how much risk the organization is willing to tolerate while pursuing strategic goals.
Which element distinguishes a risk register from a risk assessment report?