CCISO Governance, Risk & Compliance 5 — Questions and Answers
Question 1: Which of the following BEST describes the concept of 'control risk' in an audit context?
- The risk that an auditor fails to detect an existing misstatement
- The risk that a misstatement will not be prevented or detected by internal controls (Correct answer)
- The risk that the subject matter being audited contains an error before controls are applied
- The risk that an audit firm loses its professional license
Correct answer: The risk that a misstatement will not be prevented or detected by internal controls
Control risk is the probability that an organization's internal controls will fail to prevent or detect a material misstatement or security issue.
Question 2: What is the MAIN purpose of a Business Impact Analysis (BIA) in governance and continuity planning?
- To identify threat actors targeting the organization
- To determine recovery time objectives and the criticality of business functions (Correct answer)
- To calculate the annual security budget needed
- To document all software vulnerabilities across the enterprise
Correct answer: To determine recovery time objectives and the criticality of business functions
A BIA identifies critical business functions, assesses the impact of their disruption, and establishes RTOs and RPOs to guide continuity planning.
Question 3: Which governance document formally authorizes a specific system to operate within an organization, acknowledging its risks?
- System Security Plan (SSP)
- Authority to Operate (ATO) (Correct answer)
- Plan of Action and Milestones (POA&M)
- Risk Assessment Report (RAR)
Correct answer: Authority to Operate (ATO)
An Authority to Operate (ATO) is a formal decision by an authorizing official that accepts the residual risk of operating a system.
Question 4: A CISO discovers that a cloud provider is subcontracting data processing to a fourth-party vendor without notification. This PRIMARILY violates which principle?
- Least privilege
- Due diligence in vendor chain management (Correct answer)
- Data minimization
- Defense in depth
Correct answer: Due diligence in vendor chain management
Undisclosed subcontracting represents a failure of supply chain due diligence, which requires visibility and control over all parties handling organizational data.
Question 5: Which of the following is an example of a leading indicator for measuring security program effectiveness?
- Number of data breaches in the past year
- Percentage of employees who completed security awareness training this quarter (Correct answer)
- Total cost of incidents in the previous fiscal year
- Number of regulatory fines received
Correct answer: Percentage of employees who completed security awareness training this quarter
Leading indicators measure proactive activities (like training completion) that predict future security posture, as opposed to lagging indicators that measure past failures.
Question 6: When developing a compliance program, which approach ensures that controls satisfy multiple regulatory requirements simultaneously?
- Siloed compliance with separate control sets for each regulation
- A unified control framework mapped to multiple regulatory requirements (Correct answer)
- Outsourcing each regulation's compliance to a different vendor
- Sequentially achieving one certification before starting the next
Correct answer: A unified control framework mapped to multiple regulatory requirements
A unified control framework with crosswalk mappings allows a single control to satisfy multiple regulatory requirements, reducing redundancy and cost.
Question 7: What does the term 'residual risk' represent after security controls are implemented?
- The risk that was transferred to an insurance provider
- The risk that remains after all applicable controls have been applied (Correct answer)
- The total financial exposure before any controls
- The risk accepted by senior leadership in the risk register
Correct answer: The risk that remains after all applicable controls have been applied
Residual risk is the remaining level of risk exposure after inherent risk has been reduced by implementing security controls.
Which of the following BEST describes the concept of 'control risk' in an audit context?