CCISO Information Security & Risk Management 3 — Questions and Answers
Question 1: A CISO must present the security program's value to the board. Which metric BEST demonstrates the effectiveness of security controls from a business risk perspective?
- Number of firewall rules updated per quarter
- Reduction in risk exposure measured in dollar value (Correct answer)
- Total number of security incidents detected
- Percentage of employees who completed security awareness training
Correct answer: Reduction in risk exposure measured in dollar value
Boards understand financial risk; expressing risk reduction in dollar value directly connects security investments to business outcomes they can evaluate.
Question 2: Under ISO/IEC 27005, the risk evaluation step is performed to:
- Identify all assets within scope of the ISMS
- Compare risk analysis results against risk criteria to prioritize treatment (Correct answer)
- Implement controls selected from ISO/IEC 27002
- Document residual risk after controls are applied
Correct answer: Compare risk analysis results against risk criteria to prioritize treatment
Risk evaluation compares the estimated risk levels against pre-established risk criteria to determine which risks require treatment and their priority.
Question 3: Which of the following BEST represents a Key Risk Indicator (KRI) for an information security program?
- Number of patches applied in the last 30 days
- Percentage of critical systems with unpatched vulnerabilities older than 90 days (Correct answer)
- Total IT budget allocated to security tools
- Number of security team members certified
Correct answer: Percentage of critical systems with unpatched vulnerabilities older than 90 days
A KRI measures leading indicators of potential risk exposure; unpatched critical systems represent a measurable condition that predicts future breach likelihood.
Question 4: An organization wants to ensure its information security risk management aligns with enterprise risk management (ERM). The PRIMARY benefit of this alignment is:
- Reducing the number of security controls needed
- Ensuring security risks are considered alongside strategic and operational risks (Correct answer)
- Allowing the CISO to report directly to the board without intermediaries
- Automating risk assessment processes across the enterprise
Correct answer: Ensuring security risks are considered alongside strategic and operational risks
Aligning information security risk management with ERM ensures that cyber risks are viewed in the context of overall business risk, enabling better prioritization and resource allocation.
Question 5: Which statement BEST describes the purpose of a Statement of Applicability (SoA) in an ISO 27001 implementation?
- It lists all identified threats and vulnerabilities for the organization
- It documents which Annex A controls are applicable and why others are excluded (Correct answer)
- It defines the scope of the Information Security Management System
- It outlines the risk acceptance criteria approved by management
Correct answer: It documents which Annex A controls are applicable and why others are excluded
The SoA is a required ISO 27001 document that identifies which Annex A controls are applicable, justifies their inclusion, and explains why excluded controls are not relevant.
Question 6: A CISO discovers that a third-party vendor with access to sensitive customer data has not undergone a security assessment. Which risk management step should have prevented this gap?
- Risk monitoring
- Risk communication
- Risk identification (Correct answer)
- Risk treatment
Correct answer: Risk identification
Risk identification should encompass all assets and relationships including third-party vendors; failure to identify this risk source means it was excluded from the assessment scope.
Question 7: In a risk scenario analysis, the 'exposure factor' (EF) represents:
- The frequency with which a threat is expected to occur annually
- The percentage of asset value lost if a specific threat materializes (Correct answer)
- The cost of implementing a safeguard to protect an asset
- The probability that a vulnerability will be exploited
Correct answer: The percentage of asset value lost if a specific threat materializes
Exposure Factor is the proportion (percentage) of an asset's value that would be lost in a single threat event, used to calculate Single Loss Expectancy.
A CISO must present the security program's value to the board.
Which metric BEST demonstrates the effectiveness of security controls from a business risk perspective?