CCISO Governance, Risk & Compliance 4 — Questions and Answers
Question 1: Which security governance structure places the CISO directly under the CEO, independent of IT?
- Centralized IT governance model
- Decentralized security model
- Business-aligned CISO model (Correct answer)
- Federated governance model
Correct answer: Business-aligned CISO model
The business-aligned CISO model positions the CISO as a peer of the CIO, reporting to the CEO, ensuring security independence from IT operations.
Question 2: An Annual Loss Expectancy (ALE) is calculated as:
- Asset Value × Exposure Factor
- Single Loss Expectancy × Annualized Rate of Occurrence (Correct answer)
- Total Control Cost ÷ Number of Assets
- Risk Impact × Probability Score
Correct answer: Single Loss Expectancy × Annualized Rate of Occurrence
ALE = SLE × ARO, where Single Loss Expectancy is the monetary loss per incident and Annualized Rate of Occurrence is how often it happens per year.
Question 3: Which NIST publication provides a framework specifically designed for improving critical infrastructure cybersecurity?
- NIST SP 800-53
- NIST SP 800-37
- NIST Cybersecurity Framework (CSF) (Correct answer)
- NIST SP 800-171
Correct answer: NIST Cybersecurity Framework (CSF)
The NIST Cybersecurity Framework (CSF) was developed to help critical infrastructure organizations manage and reduce cybersecurity risk using Identify, Protect, Detect, Respond, and Recover functions.
Question 4: What is the primary goal of segregation of duties (SoD) as a governance control?
- Ensure all employees are cross-trained for redundancy
- Prevent any single individual from having enough access to commit and conceal fraud (Correct answer)
- Reduce the number of user accounts in the system
- Enforce least privilege by limiting access to one system per user
Correct answer: Prevent any single individual from having enough access to commit and conceal fraud
SoD ensures that critical business functions require multiple people, so no single individual can both execute and hide a fraudulent or malicious act.
Question 5: Which compliance framework is MOST relevant for organizations handling payment card data?
- SOC 2 Type II
- PCI DSS (Correct answer)
- ISO 27001
- NIST SP 800-171
Correct answer: PCI DSS
PCI DSS (Payment Card Industry Data Security Standard) is the mandatory standard for all entities that store, process, or transmit cardholder data.
Question 6: A CISO is presenting the security program's maturity to the board. Which model is BEST suited for assessing and communicating security maturity levels?
- FAIR (Factor Analysis of Information Risk)
- Capability Maturity Model Integration (CMMI) (Correct answer)
- Cybersecurity Maturity Model Certification (CMMC)
- OWASP Risk Rating Methodology
Correct answer: Capability Maturity Model Integration (CMMI)
CMMI provides a structured framework with defined maturity levels (1–5) that can be used to assess and communicate the sophistication of security processes.
Question 7: Under a risk-based audit approach, which area would an internal auditor prioritize FIRST?
- Departments with the largest headcount
- Systems last audited over three years ago regardless of risk
- Processes with the highest inherent risk and weakest controls (Correct answer)
- Business units with the highest revenue
Correct answer: Processes with the highest inherent risk and weakest controls
Risk-based auditing directs attention to areas where high inherent risk combines with inadequate controls, representing the greatest exposure.
Which security governance structure places the CISO directly under the CEO, independent of IT?