Financial Management Flashcards
7 cards from real CCISO practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Financial Management flashcards as text
A CISO identifies that a critical vendor managing customer PII has no cyber insurance. Under a shared risk model, what financial control should the CISO recommend?
Answer: Require the vendor to obtain adequate cyber liability insurance as a contractual obligation
Requiring vendors to maintain cyber liability insurance transfers financial risk back to the vendor and is a standard third-party risk management contractual control.
A CISO must present a business case for a $2M security platform. The expected annual loss (ALE) for the risk it mitigates is $800,000. What does this indicate about the investment?
Answer: The investment cost exceeds the annual expected loss, suggesting it may not be cost-effective
When control cost ($2M) exceeds the annual expected loss ($800K), a cost-benefit analysis suggests the investment is not economically justified on risk grounds alone without other factors.
Which of the following best describes the relationship between Annual Rate of Occurrence (ARO) and Annual Loss Expectancy (ALE)?
Answer: ALE = SLE × ARO
ALE is calculated by multiplying Single Loss Expectancy (the cost of one incident) by the Annual Rate of Occurrence (how often it is expected to occur per year).
A CISO is asked to reduce the security budget by 20% mid-year. What is the most appropriate first step?
Answer: Perform a risk impact assessment to identify which cuts introduce the least additional risk
Before making cuts, a risk impact assessment identifies which expenditures are critical to risk posture versus optional, enabling informed decisions that minimize exposure.
A publicly traded company's CISO must ensure that material cybersecurity incidents are disclosed per SEC rules. What is the primary financial risk of late or inaccurate disclosure?
Answer: SEC enforcement actions, fines, and shareholder litigation
Under SEC cybersecurity disclosure rules, late or inaccurate material incident reporting exposes the company to SEC enforcement, civil penalties, and securities fraud litigation.
A CISO is negotiating a cloud security contract and encounters a limitation of liability clause capping vendor damages at one month's fees. What financial risk management strategy should the CISO recommend?
Answer: Supplement with cyber insurance to cover losses exceeding the contractual cap
When contractual liability caps fall short of potential loss exposure, cyber insurance fills the financial gap between what the vendor will pay and actual breach costs.
Which financial document provides the CISO with the best view of committed but not yet spent security funds across the fiscal year?
Answer: Budget vs. actuals report with encumbrances
A budget vs. actuals report that includes encumbrances (committed but unspent funds) shows true available budget by accounting for purchase orders and contracts already in progress.