← All CISSP Flashcard Decks

Security and Risk Management Flashcards

7 cards from real CISSP practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Security and Risk Management flashcards as text
  1. Which type of security policy provides the highest-level direction and is signed by executive leadership to express management commitment to security?

    Answer: Organizational (master) security policy

    The organizational or master security policy is the top-level document that expresses executive commitment and sets the strategic direction for the entire security program.

  2. In the context of security governance, which committee typically has responsibility for approving major security investments and accepting residual risk at the enterprise level?

    Answer: Executive management / board of directors

    Ultimate risk ownership and acceptance authority rests with executive management or the board, who are accountable for organizational outcomes.

  3. Which attack surface analysis technique involves systematically identifying all entry points where untrusted data enters a system?

    Answer: Attack surface mapping / threat surface analysis

    Attack surface mapping catalogs all points where an adversary could interact with a system, enabling prioritized hardening of the most exposed areas.

  4. The Gramm-Leach-Bliley Act (GLBA) primarily requires which type of organization to protect customer financial information?

    Answer: Financial institutions

    GLBA mandates that banks, insurance companies, and other financial institutions implement safeguards to protect the privacy of consumer financial information.

  5. Which risk analysis approach assigns probability and impact using descriptive scales, is faster to perform, and is well-suited when hard data is unavailable?

    Answer: Qualitative analysis

    Qualitative analysis uses descriptive ratings (e.g., High/Medium/Low) based on expert opinion, making it faster but more subjective than quantitative methods.

  6. A security awareness program is MOST effective when it:

    Answer: Uses role-based, continuous training tied to real threats employees face

    Effective security awareness programs are ongoing, tailored to different roles, and use realistic scenarios relevant to each employee's actual work environment.

  7. Which concept describes the combination of policies, procedures, standards, and guidelines that collectively define how security is managed across an organization?

    Answer: Security governance framework

    A security governance framework integrates all security management elements—policies, processes, roles, and metrics—to ensure consistent, accountable security decision-making.