CREST Compliance, Risk & Governance 2 — Questions and Answers
Question 1: What is the purpose of a Business Impact Analysis (BIA) in risk management?
- To identify critical business functions and the impact of their disruption (Correct answer)
- To analyze the cost of security tool licenses
- To assess employee satisfaction with security policies
- To document system architecture diagrams
Correct answer: To identify critical business functions and the impact of their disruption
A BIA identifies which business processes are critical, determines the financial and operational impact of their disruption, and informs recovery priorities.
Question 2: What does RTO (Recovery Time Objective) define in business continuity planning?
- The maximum acceptable time to restore a system or process after a disruption (Correct answer)
- The amount of data that can be lost in a disaster
- The cost of recovering from an incident
- The time required to detect a security breach
Correct answer: The maximum acceptable time to restore a system or process after a disruption
RTO specifies the maximum tolerable duration of a system outage before the business impact becomes unacceptable, driving recovery infrastructure decisions.
Question 3: Which regulation requires US federal agencies to implement information security programs and report on their effectiveness?
- FISMA (Federal Information Security Modernization Act) (Correct answer)
- HIPAA
- GLBA
- FERPA
Correct answer: FISMA (Federal Information Security Modernization Act)
FISMA requires federal agencies to develop, document, and implement information security programs and report annually to Congress on their security posture.
Question 4: What is a key difference between a policy and a procedure in an information security governance framework?
- A policy states what must be done; a procedure describes how to do it (Correct answer)
- A policy is technical; a procedure is managerial
- A policy is optional; a procedure is mandatory
- They are the same document with different names
Correct answer: A policy states what must be done; a procedure describes how to do it
Policies define high-level security requirements and goals, while procedures provide step-by-step instructions for implementing and complying with those policies.
Question 5: What does a CREST-registered organization commit to in terms of professional standards?
- Employing certified professionals who have passed rigorous technical examinations and adhere to a code of conduct (Correct answer)
- Using only CREST-approved software tools
- Completing monthly vulnerability scans of client infrastructure
- Submitting annual financial audits to CREST
Correct answer: Employing certified professionals who have passed rigorous technical examinations and adhere to a code of conduct
CREST membership requires organizations to employ certified professionals, demonstrate technical competence, and operate under CREST's code of conduct and professional standards.
Question 6: Which risk assessment methodology is commonly used in US government contexts and aligns with NIST SP 800-30?
- NIST Risk Management Framework (RMF) (Correct answer)
- OCTAVE
- CRAMM
- FAIR
Correct answer: NIST Risk Management Framework (RMF)
The NIST RMF and NIST SP 800-30 provide a structured risk assessment process used across US federal agencies to categorize, select, implement, and monitor security controls.
What is the purpose of a Business Impact Analysis (BIA) in risk management?