Governance, Risk Management & Policy Development Flashcards
7 cards from real CSC practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Governance, Risk Management & Policy Development flashcards as text
A company's board of directors wants to ensure cybersecurity risk is addressed at the highest level. Which governance structure best achieves this?
Answer: Establishing a board-level cybersecurity committee with executive oversight
A board-level cybersecurity committee ensures that security risk receives executive-level attention and accountability.
Which risk treatment option involves transferring the financial impact of a risk to another party?
Answer: Risk transfer
Risk transfer shifts the financial consequences of a risk to a third party, such as through insurance or contractual agreements.
An organization's information security policy states that all employees must complete annual security awareness training. This policy is BEST classified as which type?
Answer: Advisory policy
Advisory policies recommend best practices and may include mandatory requirements like training, guiding employee behavior.
What is the PRIMARY purpose of a Risk Register in an organization?
Answer: To document identified risks, their likelihood, impact, and treatment plans
A Risk Register is a central document that captures identified risks along with their attributes and management strategies.
Under NIST's Risk Management Framework (RMF), which step involves selecting and implementing security controls?
Answer: Select and Implement
The Select and Implement step in NIST RMF involves choosing appropriate security controls and putting them into operation.
A risk assessment reveals a vulnerability with high likelihood but very low potential impact. How should this risk MOST likely be treated?
Answer: Accept the risk with monitoring in place
Low-impact risks, even with high likelihood, are often accepted with monitoring rather than incurring disproportionate mitigation costs.
Which document defines the scope, objectives, and management commitment to information security across an entire organization?
Answer: Information security policy
An information security policy is a high-level document expressing management's commitment and the organization's security objectives.