As part of a risk assessment, a security control was discovered to be inadequate. When assigning a risk owner, which of the following attributes is MOST important to consider?
An organization has acquired a new system with strict maintenance instructions and schedules. Where should this information be documented?
A multinational organization is introducing a security governance framework. The information security manager ' s concern is that regional security practices differ. Which of the following should be evaluated FIRST?
An information security team plans to strengthen authentication requirements for a customer-facing site, but there are concerns it will negatively impact the user experience. Which of the following is the information security manager ' s BEST course of action?
Which of the following considerations is MOST important when selecting a third-party intrusion detection system (IDS) vendor?
Which of the following is the BEST security control to minimize the risk of successful ransomware attacks?
A security incident has been reported within an organization. When should an information security manager contact the information owner?
Which of the following is the FIRST step to establishing an effective information security program?
An organization ' s main product is a customer-facing application delivered using Software as a Service (SaaS). The lead security engineer has just identified a major security vulnerability at the primary cloud provider. Within the organization, who is PRIMARILY accountable for the associated task?
Which of the following is the BEST source of information to support an organization ' s information security vision and strategy?
An organization learns that a third party has outsourced critical functions to another external provider. Which of the following is the information security manager ' s MOST important course of action?
Which of the following is the BEST approach to reduce unnecessary duplication of compliance activities?
Which of the following processes BEST supports the evaluation of incident response effectiveness?
Which of the following is the MOST critical input to developing policies, standards, and procedures to secure information assets?
Which of the following is the PRIMARY benefit achieved when an information security governance framework is aligned with corporate governance?
Which of the following should be triggered FIRST when unknown malware has infected an organization ' s critical system?
Which of the following should be the NEXT step after a security incident has been reported?
Which of the following is MOST important to the effectiveness of an information security program?