Which of the following is the MOST important outcome of effective risk treatment?
IT projects have gone over budget with too many security controls being added post-production. Which of the following would MOST help to ensure that relevant controls are applied to a project?
Which of the following is MOST important for the improvement of a business continuity plan (BCP)?
A business unit recently integrated the organization ' s new strong password policy into its business application which requires users to reset passwords every 30 days. The help desk is now flooded with password reset requests. Which of the following is the information security manager ' s BEST course of action to address this situation?
Which of the following is the MOST important reason for obtaining input from risk owners when implementing controls?
An organization’s human resources department is planning to migrate a legacy application to a new application in the cloud. What is the BEST way for the information security manager to support this effort?
An information security manager learns that IT personnel are not adhering to the information security policy because it creates process inefficiencies. What should the information security manager do FIRST?
A global organization is considering its geopolitical security risks. Which of the following is the information security manager ' s BEST approach?
An organization has multiple data repositories across different departments. The information security manager has been tasked with creating an enterprise strategy for protecting data. Which of the following information security initiatives should be the HIGHEST priority for the organization?
When developing an information security strategy for an organization, which of the following is MOST helpful for understanding where to focus efforts?
During which phase of a security event should an incident response team be INITIALLY engaged?
While classifying information assets an information security manager notices that several production databases do not have owners assigned to them What is the BEST way to address this situation?
Which of the following is the PRIMARY responsibility of an information security governance committee?
An information security team is investigating an alleged breach of an organization ' s network. Which of the following would be the BEST single source of evidence to review?
Which of the following is the MOST effective way to ensure information security policies are understood?
Which of the following is the MOST important consideration when evaluating the performance of existing security controls?
Regular vulnerability scanning on an organization ' s internal network has identified that many user workstations have unpatched versions of software. What is the BEST way for the information security manager to help senior management understand the related risk?
Which of the following should an information security manager do NEXT after creating a roadmap to execute the strategy for an information security program?