CSL Cybersecurity Governance & Risk Management 3 — Questions and Answers
Question 1: Which metric best measures the effectiveness of a cybersecurity governance program over time?
- Number of firewalls deployed
- Key Risk Indicators (KRIs) tracked against defined thresholds (Correct answer)
- Total IT budget allocated to security
- Number of employees in the security team
Correct answer: Key Risk Indicators (KRIs) tracked against defined thresholds
Key Risk Indicators provide measurable data points that signal whether risk levels are within acceptable governance thresholds.
Question 2: An organization's risk register shows a high-likelihood, low-impact risk. What is the most appropriate initial response?
- Immediately transfer the risk via insurance
- Accept the risk without any controls
- Implement cost-effective controls to reduce likelihood (Correct answer)
- Escalate immediately to the board
Correct answer: Implement cost-effective controls to reduce likelihood
High-likelihood, low-impact risks are prime candidates for cost-effective mitigating controls to reduce their frequency.
Question 3: What is the key distinction between a security policy and a security standard?
- Policies are technical, standards are managerial
- Policies state high-level intent while standards define specific measurable requirements (Correct answer)
- Standards apply only to vendors, policies apply to employees
- Policies are optional; standards are mandatory
Correct answer: Policies state high-level intent while standards define specific measurable requirements
Policies articulate the organization's intent and direction while standards provide the specific, measurable requirements needed to meet that intent.
Question 4: Which concept describes the maximum tolerable downtime before a business process must be restored?
- Recovery Point Objective (RPO)
- Recovery Time Objective (RTO) (Correct answer)
- Mean Time to Recover (MTTR)
- Service Level Agreement (SLA)
Correct answer: Recovery Time Objective (RTO)
Recovery Time Objective (RTO) defines the maximum acceptable time to restore a system or process after a disruption.
Question 5: A CISO presents cybersecurity risk in financial terms to the board. Which methodology is most appropriate for this quantitative approach?
- STRIDE threat modeling
- Factor Analysis of Information Risk (FAIR) (Correct answer)
- OWASP Risk Rating Methodology
- DREAD scoring
Correct answer: Factor Analysis of Information Risk (FAIR)
FAIR is a quantitative risk analysis framework that expresses cyber risk in financial terms, making it ideal for board-level communication.
Question 6: What is the purpose of a Cybersecurity Maturity Model assessment?
- To identify all active vulnerabilities in a network
- To benchmark the organization's security capabilities and identify improvement areas (Correct answer)
- To test employee phishing awareness
- To verify compliance with a specific regulation
Correct answer: To benchmark the organization's security capabilities and identify improvement areas
Maturity model assessments evaluate the current state of security capabilities against defined levels to guide strategic improvement planning.
Question 7: Which supply chain risk management practice ensures vendors meet the organization's security requirements?
- Deploying endpoint detection on vendor systems
- Conducting third-party risk assessments and requiring contractual security obligations (Correct answer)
- Blocking all vendor network access
- Assigning internal IT staff to manage vendor environments
Correct answer: Conducting third-party risk assessments and requiring contractual security obligations
Third-party risk assessments and contractual security requirements ensure vendors align with organizational security standards without requiring direct control.
Which metric best measures the effectiveness of a cybersecurity governance program over time?