Security Program Development & Management Flashcards
7 cards from real CCISO practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Security Program Development & Management flashcards as text
A CISO is evaluating the maturity of the security program using CMMI. The organization consistently follows defined, documented processes but does not yet measure process effectiveness. Which maturity level does this represent?
Answer: Level 3 – Defined
CMMI Level 3 (Defined) means processes are standardized and documented organization-wide, but measurement and control come at Level 4.
Which element distinguishes a strategic security plan from an operational security plan?
Answer: A strategic plan defines long-term security goals aligned with business direction
Strategic plans address long-term direction and alignment with the business, while operational plans handle near-term execution and day-to-day activities.
An organization wants to benchmark its security program against industry peers. Which framework is BEST suited for this purpose?
Answer: NIST Cybersecurity Framework (CSF)
The NIST CSF was designed specifically for benchmarking and communicating cybersecurity posture across industries using its tiered maturity model.
A CISO discovers that a third-party vendor has access to sensitive customer data but has not been assessed for security compliance. What is the MOST appropriate immediate action?
Answer: Conduct a vendor risk assessment and enforce contractual security requirements
Conducting a risk assessment and enforcing contractual requirements is the measured, governance-based response before escalating to more disruptive actions.
Which of the following is the BEST indicator that a security awareness program is effective?
Answer: Measurable reduction in employees clicking phishing simulation links over time
Behavioral change, such as declining phishing click rates, is the best evidence that training is actually changing employee behavior and reducing risk.
When building a security program in a decentralized organization, what is the MOST effective model for maintaining consistent security standards?
Answer: Federated model with central policy and local implementation accountability
A federated model balances central policy consistency with local flexibility, which is essential in organizations with autonomous business units.
A CISO is developing KPIs for the security program. Which KPI is MOST aligned with measuring program effectiveness rather than program activity?
Answer: Percentage of critical assets with up-to-date risk assessments
Coverage of risk assessments on critical assets measures whether the program is actually managing risk, not just performing activities.