Security Program Development & Management Flashcards
7 cards from real CCISO practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Security Program Development & Management flashcards as text
A newly appointed CISO finds the security program is reactive with no formal strategy. What should be the FIRST priority?
Answer: Conduct a comprehensive risk assessment to establish a baseline
A risk assessment establishes the current state and priorities, forming the foundation for any strategic security program development.
Which document BEST communicates the organization's commitment to information security to both internal and external stakeholders?
Answer: Information Security Policy
An Information Security Policy is the high-level governance document that formally declares the organization's commitment and sets the tone from leadership.
An organization is expanding globally and must manage security across multiple regulatory jurisdictions. What is the MOST effective approach?
Answer: Develop a baseline security framework and layer jurisdiction-specific controls on top
A baseline with layered jurisdiction-specific controls efficiently meets multiple regulatory requirements without duplicating the entire security program.
Which role in an information security governance structure is PRIMARILY responsible for accepting residual risk?
Answer: Business Process Owner / Senior Management
Risk acceptance is a business decision made by business process owners or senior management who understand the risk appetite and business impact.
A CISO wants to ensure security requirements are captured for a new cloud migration project from the start. Which practice BEST achieves this?
Answer: Participating in project initiation and including security in the business case
Integrating security at project initiation ensures requirements are built in by design rather than retrofitted, reducing cost and risk.
When presenting the security program's annual report to the board, which content is MOST important to include?
Answer: Risk posture trends, program accomplishments, and resource gaps tied to business risk
Boards need risk posture trends and business-relevant gaps, not technical details, to make informed decisions about security investment.
A CISO is building a security operations capability. Which factor MOST impacts the decision between building an in-house SOC versus using a managed SOC (MSSP)?
Answer: Cost, required expertise level, and need for customized detection for the business
The build-vs-buy decision for a SOC is primarily driven by cost, the specialized expertise required, and whether detection needs are generic or highly customized.