Information Security & Risk Management Flashcards
7 cards from real CCISO practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Information Security & Risk Management flashcards as text
A CISO must present the security program's value to the board. Which metric BEST demonstrates the effectiveness of security controls from a business risk perspective?
Answer: Reduction in risk exposure measured in dollar value
Boards understand financial risk; expressing risk reduction in dollar value directly connects security investments to business outcomes they can evaluate.
Under ISO/IEC 27005, the risk evaluation step is performed to:
Answer: Compare risk analysis results against risk criteria to prioritize treatment
Risk evaluation compares the estimated risk levels against pre-established risk criteria to determine which risks require treatment and their priority.
Which of the following BEST represents a Key Risk Indicator (KRI) for an information security program?
Answer: Percentage of critical systems with unpatched vulnerabilities older than 90 days
A KRI measures leading indicators of potential risk exposure; unpatched critical systems represent a measurable condition that predicts future breach likelihood.
An organization wants to ensure its information security risk management aligns with enterprise risk management (ERM). The PRIMARY benefit of this alignment is:
Answer: Ensuring security risks are considered alongside strategic and operational risks
Aligning information security risk management with ERM ensures that cyber risks are viewed in the context of overall business risk, enabling better prioritization and resource allocation.
Which statement BEST describes the purpose of a Statement of Applicability (SoA) in an ISO 27001 implementation?
Answer: It documents which Annex A controls are applicable and why others are excluded
The SoA is a required ISO 27001 document that identifies which Annex A controls are applicable, justifies their inclusion, and explains why excluded controls are not relevant.
A CISO discovers that a third-party vendor with access to sensitive customer data has not undergone a security assessment. Which risk management step should have prevented this gap?
Answer: Risk identification
Risk identification should encompass all assets and relationships including third-party vendors; failure to identify this risk source means it was excluded from the assessment scope.
In a risk scenario analysis, the 'exposure factor' (EF) represents:
Answer: The percentage of asset value lost if a specific threat materializes
Exposure Factor is the proportion (percentage) of an asset's value that would be lost in a single threat event, used to calculate Single Loss Expectancy.