โ† All CCISO Flashcard Decks

Governance, Risk & Compliance Flashcards

7 cards from real CCISO practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Governance, Risk & Compliance flashcards as text
  1. Which risk treatment option involves transferring the financial impact of a risk to a third party?

    Answer: Risk transference

    Risk transference shifts the financial burden of a risk to another party, such as through cyber insurance or outsourcing.

  2. A CISO needs to align the security program with business objectives. Which framework is MOST appropriate for mapping security controls to business goals?

    Answer: COBIT 2019

    COBIT 2019 is specifically designed to align IT governance, including security, with overall enterprise business objectives.

  3. Under GDPR, what is the maximum time frame for reporting a personal data breach to the supervisory authority after becoming aware of it?

    Answer: 72 hours

    GDPR Article 33 requires notification to the supervisory authority within 72 hours of becoming aware of a personal data breach.

  4. Which of the following BEST describes the purpose of a Statement of Applicability (SoA) in ISO 27001?

    Answer: Lists applicable controls and justifies inclusions and exclusions

    The SoA documents which Annex A controls are applicable, their implementation status, and the justification for including or excluding each control.

  5. A company operates in multiple jurisdictions with conflicting privacy laws. What is the BEST governance approach to address this?

    Answer: Implement controls that satisfy the most stringent applicable regulation

    Implementing the most stringent applicable controls ensures compliance across all jurisdictions while minimizing legal risk.

  6. Which metric BEST helps a CISO demonstrate the business value of a security program to the board?

    Answer: Return on Security Investment (ROSI)

    ROSI translates security investments into financial terms that resonate with business leadership, demonstrating cost-benefit value.

  7. What is the PRIMARY purpose of a security steering committee in an enterprise?

    Answer: To provide executive oversight and strategic direction for the security program

    A security steering committee provides cross-functional executive governance, ensuring the security program aligns with business strategy.