CTO IT Governance & Risk Management 3 β Questions and Answers
Question 1: Under ISO/IEC 27001, what is the purpose of a Statement of Applicability (SoA)?
- To document all identified information security risks
- To list all controls selected or excluded and provide justification for each (Correct answer)
- To define the scope of the ISMS
- To record the results of internal audits
Correct answer: To list all controls selected or excluded and provide justification for each
The SoA documents which Annex A controls are applicable and implemented, which are excluded, and the justifications for all inclusion/exclusion decisions.
Question 2: A CTO must prioritize IT investments under budget constraints. Which governance tool best facilitates transparent prioritization based on business value and risk?
- IT project Gantt chart
- IT portfolio management framework (Correct answer)
- Incident response plan
- Service catalog
Correct answer: IT portfolio management framework
IT portfolio management provides a structured approach to evaluating, prioritizing, and balancing IT investments based on strategic value, cost, and risk.
Question 3: What distinguishes a Key Risk Indicator (KRI) from a Key Performance Indicator (KPI)?
- KRIs measure past performance while KPIs predict future risk
- KRIs provide early warning signals of increasing risk exposure while KPIs measure achievement against targets (Correct answer)
- KRIs are used only by the security team while KPIs are used by all departments
- KRIs require board approval while KPIs do not
Correct answer: KRIs provide early warning signals of increasing risk exposure while KPIs measure achievement against targets
KRIs are forward-looking metrics that signal potential risk before it materializes, whereas KPIs measure how well current objectives are being achieved.
Question 4: In NIST SP 800-37 (Risk Management Framework), which step involves categorizing information systems based on the potential impact of a security breach?
- Select
- Implement
- Categorize (Correct answer)
- Authorize
Correct answer: Categorize
The Categorize step uses FIPS 199 criteria to classify systems by the potential impact (low, moderate, high) of a confidentiality, integrity, or availability breach.
Question 5: Which governance concept requires that no single individual controls all phases of a critical transaction or process?
- Least privilege
- Separation of duties (Correct answer)
- Defense in depth
- Need-to-know
Correct answer: Separation of duties
Separation of duties divides critical tasks among multiple individuals to reduce fraud risk and errors by ensuring no one person can complete a sensitive transaction alone.
Question 6: A company's IT risk register shows a vulnerability with Critical severity but Low likelihood of exploitation. Following a qualitative risk matrix, how should this be treated?
- Always remediate immediately regardless of likelihood
- Assess the combined risk rating and prioritize based on the resulting risk score (Correct answer)
- Ignore it because likelihood is low
- Treat it the same as a High severity, High likelihood risk
Correct answer: Assess the combined risk rating and prioritize based on the resulting risk score
A qualitative risk matrix combines severity and likelihood to produce an overall risk rating, which should drive prioritization rather than treating either dimension in isolation.
Question 7: What is the main distinction between IT governance and IT management as defined by ISO/IEC 38500?
- Governance is performed by vendors; management is performed internally
- Governance involves evaluating, directing, and monitoring; management involves planning and operating (Correct answer)
- Governance is a subset of management
- Management sets policy while governance executes it
Correct answer: Governance involves evaluating, directing, and monitoring; management involves planning and operating
ISO/IEC 38500 defines governance as the system by which IT use is directed and controlled (evaluate, direct, monitor), while management plans, builds, and operates IT in alignment with those directions.
Under ISO/IEC 27001, what is the purpose of a Statement of Applicability (SoA)?