SSCP Security Policies & Risk Management 4 — Questions and Answers
Question 1: Which risk analysis approach produces results expressed in monetary terms such as dollar loss per year?
- Qualitative risk analysis
- Quantitative risk analysis (Correct answer)
- Semi-quantitative risk analysis
- Delphi method
Correct answer: Quantitative risk analysis
Quantitative risk analysis uses mathematical formulas and monetary values (e.g., ALE = SLE × ARO) to express risk in financial terms.
Question 2: An organization's acceptable use policy (AUP) is updated. What must happen before the policy takes effect for existing employees?
- The policy must be filed with a regulatory body
- Employees must be notified and must acknowledge the updated policy (Correct answer)
- The IT department must implement technical controls first
- Legal counsel must certify compliance with all regulations
Correct answer: Employees must be notified and must acknowledge the updated policy
Employees must be informed of policy changes and provide acknowledgment to ensure the policy is both known and enforceable.
Question 3: In the context of risk management, what does 'risk appetite' mean?
- The maximum possible loss an organization could suffer
- The total amount of risk an organization is willing to accept in pursuit of its objectives (Correct answer)
- The residual risk remaining after controls are applied
- The cost of implementing all available security controls
Correct answer: The total amount of risk an organization is willing to accept in pursuit of its objectives
Risk appetite is the board-level statement of how much risk the organization is willing to tolerate while pursuing its strategic goals.
Question 4: A hospital must comply with HIPAA while also meeting state privacy laws that are stricter. Which standard should their security policy follow?
- HIPAA, since federal law supersedes state law
- The stricter state law, since it provides greater protection (Correct answer)
- Whichever law is cheaper to implement
- Neither — the hospital should adopt ISO 27001 instead
Correct answer: The stricter state law, since it provides greater protection
HIPAA establishes a minimum federal floor; states may enact stricter privacy laws, and organizations must comply with the most stringent applicable requirement.
Question 5: What is the purpose of a control gap analysis in risk management?
- To measure network latency between security devices
- To identify where current controls fail to meet required security objectives (Correct answer)
- To calculate the financial cost of each implemented control
- To assign ownership of risks to business units
Correct answer: To identify where current controls fail to meet required security objectives
A control gap analysis compares current control implementation against requirements or standards to identify deficiencies that need remediation.
Question 6: Which risk response involves purchasing cyber liability insurance?
- Risk avoidance
- Risk mitigation
- Risk transfer (Correct answer)
- Risk acceptance
Correct answer: Risk transfer
Cyber liability insurance transfers the financial consequences of a risk event to an insurer in exchange for premium payments.
Question 7: A new regulation requires annual third-party security audits. Which policy type would formally mandate this requirement within an organization?
- Acceptable use policy
- Regulatory compliance policy (Correct answer)
- Incident response policy
- Change management policy
Correct answer: Regulatory compliance policy
Regulatory compliance policies document obligations arising from laws and regulations and mandate the activities required to satisfy them.
Which risk analysis approach produces results expressed in monetary terms such as dollar loss per year?