Governance, Risk & Compliance Flashcards
7 cards from real CCISO practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Governance, Risk & Compliance flashcards as text
Which risk treatment option involves transferring the financial impact of a risk to a third party?
Answer: Risk transference
Risk transference shifts the financial burden of a risk to another party, such as through cyber insurance or outsourcing.
A CISO needs to align the security program with business objectives. Which framework is MOST appropriate for mapping security controls to business goals?
Answer: COBIT 2019
COBIT 2019 is specifically designed to align IT governance, including security, with overall enterprise business objectives.
Under GDPR, what is the maximum time frame for reporting a personal data breach to the supervisory authority after becoming aware of it?
Answer: 72 hours
GDPR Article 33 requires notification to the supervisory authority within 72 hours of becoming aware of a personal data breach.
Which of the following BEST describes the purpose of a Statement of Applicability (SoA) in ISO 27001?
Answer: Lists applicable controls and justifies inclusions and exclusions
The SoA documents which Annex A controls are applicable, their implementation status, and the justification for including or excluding each control.
A company operates in multiple jurisdictions with conflicting privacy laws. What is the BEST governance approach to address this?
Answer: Implement controls that satisfy the most stringent applicable regulation
Implementing the most stringent applicable controls ensures compliance across all jurisdictions while minimizing legal risk.
Which metric BEST helps a CISO demonstrate the business value of a security program to the board?
Answer: Return on Security Investment (ROSI)
ROSI translates security investments into financial terms that resonate with business leadership, demonstrating cost-benefit value.
What is the PRIMARY purpose of a security steering committee in an enterprise?
Answer: To provide executive oversight and strategic direction for the security program
A security steering committee provides cross-functional executive governance, ensuring the security program aligns with business strategy.