CSPM CSPM Security Governance & Leadership 1 — Questions and Answers
Question 1: In security project management, which governance document defines the acceptable use of organizational IT resources by employees?
- Incident response plan
- Acceptable Use Policy (AUP) (Correct answer)
- Business continuity plan
- System security plan
Correct answer: Acceptable Use Policy (AUP)
An Acceptable Use Policy (AUP) establishes the rules and restrictions governing how employees may use organizational technology assets, networks, and data.
Question 2: Which role in a security governance structure is ultimately accountable for accepting residual risk on behalf of the organization?
- Chief Information Security Officer (CISO)
- Security project manager
- Authorizing Official (AO) (Correct answer)
- System owner
Correct answer: Authorizing Official (AO)
The Authorizing Official (AO), typically a senior executive, formally accepts residual risk and grants the Authority to Operate (ATO) for a system under NIST RMF.
Question 3: A security governance framework ensures strategic alignment by linking security objectives to:
- Individual employee performance reviews
- Overall business goals and mission objectives (Correct answer)
- Vendor contract terms and SLAs
- Technical patch management schedules
Correct answer: Overall business goals and mission objectives
Effective security governance aligns cybersecurity investments and objectives with the organization's overarching business strategy, ensuring security enables rather than hinders mission success.
Question 4: What is the primary function of a security steering committee in a large organization?
- Performing hands-on penetration testing
- Providing executive oversight and strategic direction for the security program (Correct answer)
- Writing detailed technical security policies
- Managing day-to-day incident response activities
Correct answer: Providing executive oversight and strategic direction for the security program
A security steering committee brings together executive and senior leadership to set strategic security priorities, approve major decisions, and ensure program alignment with business goals.
Question 5: The concept of 'separation of duties' in security governance is primarily designed to:
- Reduce employee workload by dividing tasks
- Prevent fraud and errors by ensuring no single person controls an entire process (Correct answer)
- Speed up security project delivery timelines
- Satisfy PCI-DSS network segmentation requirements
Correct answer: Prevent fraud and errors by ensuring no single person controls an entire process
Separation of duties divides critical processes among multiple individuals to reduce the risk of insider fraud, error, or abuse by ensuring no single employee has complete control.
Question 6: Which security governance principle requires that users be granted only the minimum access rights necessary to perform their job functions?
- Need-to-know
- Least privilege (Correct answer)
- Defense in depth
- Due diligence
Correct answer: Least privilege
The principle of least privilege restricts user access rights to only what is strictly required for their role, minimizing the potential damage from compromised accounts or insider threats.
In security project management, which governance document defines the acceptable use of organizational IT resources by employees?