โ† All CCISO Flashcard Decks

Information Security & Risk Management Flashcards

7 cards from real CCISO practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Information Security & Risk Management flashcards as text
  1. A CISO is establishing a security governance structure. Which of the following BEST defines the role of a security steering committee?

    Answer: To provide cross-functional oversight and strategic direction for the security program

    A security steering committee provides executive-level, cross-functional governance by aligning security strategy with business objectives and approving major security program decisions.

  2. When applying FAIR (Factor Analysis of Information Risk), the term 'Loss Event Frequency' refers to:

    Answer: How often a loss event is expected to occur within a defined timeframe

    In the FAIR model, Loss Event Frequency measures how often loss events are expected to occur in a given period, combining threat event frequency and vulnerability.

  3. An organization's risk appetite statement should PRIMARILY be defined by:

    Answer: The board of directors or executive leadership aligned with business strategy

    Risk appetite reflects the organization's willingness to accept risk in pursuit of business objectives and must be set by the board or executive leadership to align with strategic direction.

  4. Which security control category BEST describes a business continuity plan?

    Answer: Corrective control

    A business continuity plan is a corrective control because it is designed to restore operations and recover from a disruptive event after it has occurred.

  5. A CISO is reviewing third-party risk. Which contractual mechanism BEST ensures the vendor maintains adequate security controls over time?

    Answer: Right-to-audit clause in the service agreement

    A right-to-audit clause gives the organization the contractual right to assess the vendor's security controls periodically, ensuring ongoing compliance with security requirements.

  6. Data classification programs are PRIMARILY intended to:

    Answer: Ensure that information is protected at a level commensurate with its value and sensitivity

    Data classification establishes categories of sensitivity so that appropriate security controls can be applied proportionally to protect data based on its business value and risk.

  7. In risk management, the PRIMARY difference between a threat and a vulnerability is that:

    Answer: A threat is a potential cause of harm while a vulnerability is a weakness that can be exploited

    A threat is any potential danger or adverse event, while a vulnerability is a specific weakness in a system, process, or control that a threat can exploit to cause harm.