CCISO Information Security & Risk Management 5 — Questions and Answers
Question 1: An organization is implementing security metrics. Which characteristic is MOST important for a metric to be useful for security management decisions?
- The metric should be technically complex to demonstrate program sophistication
- The metric should be actionable and tied to a specific decision or outcome (Correct answer)
- The metric should track the largest possible volume of security events
- The metric should be self-reported by the team being measured
Correct answer: The metric should be actionable and tied to a specific decision or outcome
Effective security metrics must be actionable, meaning they provide information that can drive a specific management decision or corrective action.
Question 2: A CISO notices that control effectiveness reviews are only performed annually. What is the PRIMARY risk of infrequent control assessments?
- Regulatory penalties for non-compliance with assessment schedules
- Controls may become ineffective due to environmental changes without detection (Correct answer)
- Employees may lose familiarity with security policies and procedures
- Annual assessments are too costly for most security budgets
Correct answer: Controls may become ineffective due to environmental changes without detection
Infrequent control assessments create a window where controls degraded by system changes, personnel turnover, or new threats go undetected, increasing residual risk.
Question 3: Which of the following BEST describes the 'defense in depth' principle as applied to information security risk management?
- Deploying a single, highly robust control to eliminate a critical risk
- Layering multiple independent controls so that failure of one does not compromise security (Correct answer)
- Focusing all security investment on the network perimeter
- Using encryption as the primary mechanism for all security requirements
Correct answer: Layering multiple independent controls so that failure of one does not compromise security
Defense in depth implements multiple overlapping layers of controls so that if one control fails or is bypassed, additional controls continue to provide protection.
Question 4: Under the NIST Cybersecurity Framework (CSF), which function focuses on developing and implementing appropriate activities to identify cybersecurity risks?
- Protect
- Identify (Correct answer)
- Detect
- Respond
Correct answer: Identify
The Identify function of the NIST CSF develops organizational understanding of managing cybersecurity risk to systems, assets, data, and capabilities.
Question 5: A CISO is evaluating whether to implement a new security control. The cost of the control is $50,000 annually and the ALE before the control is $120,000. The ALE after the control is $40,000. What is the value of implementing the control?
- $30,000 net benefit (Correct answer)
- $80,000 net benefit
- $120,000 net benefit
- $70,000 net benefit
Correct answer: $30,000 net benefit
The control saves $80,000 (ALE reduction from $120K to $40K) but costs $50,000, yielding a net benefit of $30,000 annually.
Question 6: Which of the following is an example of a leading indicator in security risk management?
- Number of data breaches reported in the last fiscal year
- Percentage of critical vulnerabilities unpatched beyond SLA (Correct answer)
- Total fines paid due to regulatory non-compliance
- Number of customers affected by the last security incident
Correct answer: Percentage of critical vulnerabilities unpatched beyond SLA
Unpatched vulnerabilities beyond SLA is a leading indicator because it signals increased future risk before a breach occurs, unlike lagging indicators that measure past events.
Question 7: When developing a risk treatment plan, which element is ESSENTIAL to include to ensure accountability and track progress?
- A detailed technical architecture diagram for each control
- Named ownership, target completion dates, and success criteria for each action (Correct answer)
- Approval signatures from all department heads in the organization
- A full cost-benefit analysis for every possible control alternative
Correct answer: Named ownership, target completion dates, and success criteria for each action
A risk treatment plan must assign clear ownership, deadlines, and measurable success criteria so that progress can be tracked and accountability maintained.
An organization is implementing security metrics.
Which characteristic is MOST important for a metric to be useful for security management decisions?