CCISO Information Security & Risk Management 4 — Questions and Answers
Question 1: A CISO is establishing a security governance structure. Which of the following BEST defines the role of a security steering committee?
- To perform day-to-day management of security operations center activities
- To provide cross-functional oversight and strategic direction for the security program (Correct answer)
- To conduct technical vulnerability assessments on critical systems
- To review and approve individual security incident response actions
Correct answer: To provide cross-functional oversight and strategic direction for the security program
A security steering committee provides executive-level, cross-functional governance by aligning security strategy with business objectives and approving major security program decisions.
Question 2: When applying FAIR (Factor Analysis of Information Risk), the term 'Loss Event Frequency' refers to:
- The dollar value of losses expected from a single security event
- How often a loss event is expected to occur within a defined timeframe (Correct answer)
- The probability that a threat agent will successfully exploit a vulnerability
- The magnitude of financial harm caused by a successful attack
Correct answer: How often a loss event is expected to occur within a defined timeframe
In the FAIR model, Loss Event Frequency measures how often loss events are expected to occur in a given period, combining threat event frequency and vulnerability.
Question 3: An organization's risk appetite statement should PRIMARILY be defined by:
- The CISO based on technical risk tolerance thresholds
- The board of directors or executive leadership aligned with business strategy (Correct answer)
- Compliance requirements from applicable regulatory frameworks
- The results of the most recent penetration test
Correct answer: The board of directors or executive leadership aligned with business strategy
Risk appetite reflects the organization's willingness to accept risk in pursuit of business objectives and must be set by the board or executive leadership to align with strategic direction.
Question 4: Which security control category BEST describes a business continuity plan?
- Preventive control
- Detective control
- Corrective control (Correct answer)
- Deterrent control
Correct answer: Corrective control
A business continuity plan is a corrective control because it is designed to restore operations and recover from a disruptive event after it has occurred.
Question 5: A CISO is reviewing third-party risk. Which contractual mechanism BEST ensures the vendor maintains adequate security controls over time?
- Non-disclosure agreement (NDA)
- Right-to-audit clause in the service agreement (Correct answer)
- Indemnification clause limiting liability
- Service Level Agreement (SLA) defining uptime requirements
Correct answer: Right-to-audit clause in the service agreement
A right-to-audit clause gives the organization the contractual right to assess the vendor's security controls periodically, ensuring ongoing compliance with security requirements.
Question 6: Data classification programs are PRIMARILY intended to:
- Define the technical architecture for data storage systems
- Ensure that information is protected at a level commensurate with its value and sensitivity (Correct answer)
- Identify personnel authorized to access classified government information
- Comply with international data transfer regulations automatically
Correct answer: Ensure that information is protected at a level commensurate with its value and sensitivity
Data classification establishes categories of sensitivity so that appropriate security controls can be applied proportionally to protect data based on its business value and risk.
Question 7: In risk management, the PRIMARY difference between a threat and a vulnerability is that:
- Threats are internal while vulnerabilities are always external in origin
- A threat is a potential cause of harm while a vulnerability is a weakness that can be exploited (Correct answer)
- Vulnerabilities can be eliminated entirely while threats cannot
- Threats apply only to physical security while vulnerabilities apply to cybersecurity
Correct answer: A threat is a potential cause of harm while a vulnerability is a weakness that can be exploited
A threat is any potential danger or adverse event, while a vulnerability is a specific weakness in a system, process, or control that a threat can exploit to cause harm.
A CISO is establishing a security governance structure.
Which of the following BEST defines the role of a security steering committee?