GRC IT Governance and Cybersecurity 3 — Questions and Answers
Question 1: A CISO presents a risk appetite statement to the board. What does this statement primarily define?
- The level of risk the organization is willing to accept in pursuit of its objectives (Correct answer)
- The list of all identified threats and vulnerabilities
- The budget allocated to cybersecurity controls
- The technical specifications of security tools deployed
Correct answer: The level of risk the organization is willing to accept in pursuit of its objectives
Risk appetite defines the amount and type of risk an organization is willing to accept while pursuing its strategic goals.
Question 2: Which cybersecurity governance model separates ownership of data from custody and use, assigning accountability to a named individual for each data set?
- Data stewardship model (Correct answer)
- Zero trust architecture
- Defense-in-depth model
- Shared responsibility model
Correct answer: Data stewardship model
Data stewardship assigns named data owners accountable for data classification, protection, and lifecycle management across the organization.
Question 3: Which ISO standard provides guidance specifically on information security governance for boards and senior executives?
- ISO/IEC 27014 (Correct answer)
- ISO/IEC 27001
- ISO/IEC 27005
- ISO/IEC 27035
Correct answer: ISO/IEC 27014
ISO/IEC 27014 provides guidance on concepts and principles for the governance of information security at the organizational level.
Question 4: An organization uses a RACI matrix for its cybersecurity program. What does the 'A' in RACI represent?
- Accountable — the person who owns the outcome and signs off (Correct answer)
- Authorized — the person permitted to access the system
- Auditable — the process that can be independently reviewed
- Assigned — the team given the task to complete
Correct answer: Accountable — the person who owns the outcome and signs off
In a RACI matrix, 'Accountable' designates the single person who is ultimately answerable for the correct completion of a task or decision.
Question 5: When implementing IT governance controls, what is the primary purpose of segregation of duties (SoD)?
- To prevent fraud and errors by ensuring no single person controls all aspects of a critical process (Correct answer)
- To distribute workload evenly among team members
- To reduce training costs by specializing employee roles
- To simplify audit trails by limiting system access
Correct answer: To prevent fraud and errors by ensuring no single person controls all aspects of a critical process
Segregation of duties prevents conflicts of interest and reduces the risk of fraud or undetected errors by requiring multiple people to complete sensitive transactions.
Question 6: A cybersecurity policy states that all employees must complete annual security awareness training. Which governance element does this policy represent?
- Directive control (Correct answer)
- Preventive technical control
- Detective control
- Corrective control
Correct answer: Directive control
A directive control establishes rules or requirements that guide behavior, such as mandatory training policies.
Question 7: Under the NIST Cybersecurity Framework, which function involves identifying assets, risks, and governance requirements?
- Identify (Correct answer)
- Protect
- Detect
- Respond
Correct answer: Identify
The 'Identify' function establishes an organizational understanding of cybersecurity risks to systems, assets, data, and capabilities.
A CISO presents a risk appetite statement to the board.
What does this statement primarily define?