โ† All CSC Flashcard Decks

Governance, Risk Management & Policy Development Flashcards

7 cards from real CSC practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Governance, Risk Management & Policy Development flashcards as text
  1. A security policy review committee finds that a policy has not been updated in four years. Which risk does this PRIMARILY create?

    Answer: Non-compliance with current regulations and evolving threats

    Outdated policies may not reflect current regulatory requirements or the modern threat landscape, exposing the organization to compliance and security gaps.

  2. Under ISO/IEC 27001, what is the purpose of the Statement of Applicability (SoA)?

    Answer: To document which controls are applicable, included, or excluded along with justifications

    The Statement of Applicability documents which Annex A controls are applicable to the organization and provides justifications for inclusions and exclusions.

  3. Which metric is used in quantitative risk analysis to represent the expected monetary loss from a single risk event?

    Answer: Single Loss Expectancy (SLE)

    Single Loss Expectancy (SLE) represents the expected financial loss from a single occurrence of a specific risk event.

  4. An organization operates in a highly regulated industry. Which approach to policy development BEST ensures compliance?

    Answer: Aligning policies directly with applicable laws, regulations, and standards

    Policies must be grounded in applicable legal and regulatory requirements to ensure the organization meets its compliance obligations.

  5. Which of the following is an example of a preventive security control from a governance perspective?

    Answer: Mandatory access control policy

    A mandatory access control policy is preventive because it restricts access before unauthorized activity can occur.

  6. What is the PRIMARY difference between a policy and a standard in security documentation hierarchy?

    Answer: Policies state what must be done; standards specify how it must be done

    Policies define high-level requirements and intent, while standards provide specific, mandatory technical or procedural requirements to fulfill the policy.

  7. A CISO wants to demonstrate the ROI of cybersecurity investments to the board. Which approach is MOST effective?

    Answer: Translating risk reduction into avoided financial losses and business value

    Expressing cybersecurity value in financial and business terms (avoided losses, risk reduction) resonates most with board-level decision makers.