← All CCISO Flashcard Decks

Governance, Risk & Compliance Flashcards

7 cards from real CCISO practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Governance, Risk & Compliance flashcards as text
  1. Which security governance structure places the CISO directly under the CEO, independent of IT?

    Answer: Business-aligned CISO model

    The business-aligned CISO model positions the CISO as a peer of the CIO, reporting to the CEO, ensuring security independence from IT operations.

  2. An Annual Loss Expectancy (ALE) is calculated as:

    Answer: Single Loss Expectancy × Annualized Rate of Occurrence

    ALE = SLE × ARO, where Single Loss Expectancy is the monetary loss per incident and Annualized Rate of Occurrence is how often it happens per year.

  3. Which NIST publication provides a framework specifically designed for improving critical infrastructure cybersecurity?

    Answer: NIST Cybersecurity Framework (CSF)

    The NIST Cybersecurity Framework (CSF) was developed to help critical infrastructure organizations manage and reduce cybersecurity risk using Identify, Protect, Detect, Respond, and Recover functions.

  4. What is the primary goal of segregation of duties (SoD) as a governance control?

    Answer: Prevent any single individual from having enough access to commit and conceal fraud

    SoD ensures that critical business functions require multiple people, so no single individual can both execute and hide a fraudulent or malicious act.

  5. Which compliance framework is MOST relevant for organizations handling payment card data?

    Answer: PCI DSS

    PCI DSS (Payment Card Industry Data Security Standard) is the mandatory standard for all entities that store, process, or transmit cardholder data.

  6. A CISO is presenting the security program's maturity to the board. Which model is BEST suited for assessing and communicating security maturity levels?

    Answer: Capability Maturity Model Integration (CMMI)

    CMMI provides a structured framework with defined maturity levels (1–5) that can be used to assess and communicate the sophistication of security processes.

  7. Under a risk-based audit approach, which area would an internal auditor prioritize FIRST?

    Answer: Processes with the highest inherent risk and weakest controls

    Risk-based auditing directs attention to areas where high inherent risk combines with inadequate controls, representing the greatest exposure.