CSC Governance, Risk Management & Policy Development 2 — Questions and Answers
Question 1: A company's board of directors wants to ensure cybersecurity risk is addressed at the highest level. Which governance structure best achieves this?
- Delegating all security decisions to the CISO
- Establishing a board-level cybersecurity committee with executive oversight (Correct answer)
- Requiring IT to report risks only during annual audits
- Outsourcing risk management to a third-party vendor
Correct answer: Establishing a board-level cybersecurity committee with executive oversight
A board-level cybersecurity committee ensures that security risk receives executive-level attention and accountability.
Question 2: Which risk treatment option involves transferring the financial impact of a risk to another party?
- Risk avoidance
- Risk mitigation
- Risk acceptance
- Risk transfer (Correct answer)
Correct answer: Risk transfer
Risk transfer shifts the financial consequences of a risk to a third party, such as through insurance or contractual agreements.
Question 3: An organization's information security policy states that all employees must complete annual security awareness training. This policy is BEST classified as which type?
- Technical policy
- Advisory policy (Correct answer)
- Regulatory policy
- Informative policy
Correct answer: Advisory policy
Advisory policies recommend best practices and may include mandatory requirements like training, guiding employee behavior.
Question 4: What is the PRIMARY purpose of a Risk Register in an organization?
- To list all cybersecurity vendors used by the organization
- To document identified risks, their likelihood, impact, and treatment plans (Correct answer)
- To store audit findings from external assessors
- To record all security incidents that have occurred
Correct answer: To document identified risks, their likelihood, impact, and treatment plans
A Risk Register is a central document that captures identified risks along with their attributes and management strategies.
Question 5: Under NIST's Risk Management Framework (RMF), which step involves selecting and implementing security controls?
- Categorize
- Authorize
- Select and Implement (Correct answer)
- Assess
Correct answer: Select and Implement
The Select and Implement step in NIST RMF involves choosing appropriate security controls and putting them into operation.
Question 6: A risk assessment reveals a vulnerability with high likelihood but very low potential impact. How should this risk MOST likely be treated?
- Accept the risk with monitoring in place (Correct answer)
- Immediately escalate to board level
- Transfer the risk via cyber insurance
- Implement maximum-cost controls regardless of expense
Correct answer: Accept the risk with monitoring in place
Low-impact risks, even with high likelihood, are often accepted with monitoring rather than incurring disproportionate mitigation costs.
Question 7: Which document defines the scope, objectives, and management commitment to information security across an entire organization?
- Security procedure
- Information security policy (Correct answer)
- System security plan
- Risk assessment report
Correct answer: Information security policy
An information security policy is a high-level document expressing management's commitment and the organization's security objectives.
A company's board of directors wants to ensure cybersecurity risk is addressed at the highest level.
Which governance structure best achieves this?