Governance, Risk Management & Policy Development Flashcards
7 cards from real CSC practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Governance, Risk Management & Policy Development flashcards as text
An organization is evaluating risks using a qualitative approach. Which method are they MOST likely using?
Answer: Rating risks as High, Medium, or Low based on judgment
Qualitative risk analysis uses descriptive ratings like High, Medium, or Low rather than precise numerical calculations.
Which governance framework provides guidance specifically designed for IT governance and aligns IT goals with business objectives?
Answer: COBIT
COBIT (Control Objectives for Information and Related Technologies) is an IT governance framework that aligns IT with business goals.
A newly hired CISO wants to develop a cybersecurity strategy aligned with business goals. What should be the FIRST step?
Answer: Conduct a business impact analysis tied to security risks
Understanding business impacts of security risks ensures that the cybersecurity strategy directly supports organizational objectives.
What does the term 'residual risk' refer to?
Answer: The risk that remains after controls have been implemented
Residual risk is the level of risk that persists after security controls and mitigations have been applied.
Which role is TYPICALLY responsible for approving an organization's information security policies?
Answer: Senior management or executive leadership
Information security policies require approval from senior management or executives to carry organizational authority and accountability.
An organization wants to measure the effectiveness of its security controls on an ongoing basis. Which governance activity supports this?
Answer: Continuous monitoring
Continuous monitoring provides ongoing visibility into control effectiveness and security posture rather than point-in-time snapshots.
Which of the following BEST describes the relationship between a threat, a vulnerability, and a risk?
Answer: A threat exploits a vulnerability to create risk
Risk arises when a threat agent is capable of exploiting a vulnerability, potentially causing harm to an asset.