Deck 1: Understanding Cybersecurity Policy and Governance
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Unlock Deck
Sign up to unlock the cards in this deck!
Unlock Deck
Unlock Deck
1/20
Play
Full screen (f)
Deck 1: Understanding Cybersecurity Policy and Governance
1
Which of the following elements ensures a policy is enforceable?
A) Compliance can be measured.
B) Appropriate sanctions are applied when the policy is violated.
C) Appropriate administrative, technical, and physical controls are put in place to support the policy.
D) All of the above
A) Compliance can be measured.
B) Appropriate sanctions are applied when the policy is violated.
C) Appropriate administrative, technical, and physical controls are put in place to support the policy.
D) All of the above
All of the above
2
FERPA protects which of the following?
A) Medical records
B) Educational records
C) Personally identifiable information
D) Financial records
A) Medical records
B) Educational records
C) Personally identifiable information
D) Financial records
Educational records
3
Which of the following is an example of an information asset?
A) Business plans
B) Employee records
C) Company reputation
D) All of the above
A) Business plans
B) Employee records
C) Company reputation
D) All of the above
All of the above
4
Policy implementation and enforcement are part of which of the following phases of the cybersecurity policy life cycle?
A) Develop
B) Review
C) Adopt
D) Publish
A) Develop
B) Review
C) Adopt
D) Publish
Unlock Deck
Unlock for access to all 20 flashcards in this deck.
Unlock Deck
k this deck
5
Which of the following is the correct order of the policy life cycle?
A) Review, develop, adopt, publish
B) Develop, publish, adopt, review
C) Publish, develop, review, adopt
D) Review, adopt, develop, publish
A) Review, develop, adopt, publish
B) Develop, publish, adopt, review
C) Publish, develop, review, adopt
D) Review, adopt, develop, publish
Unlock Deck
Unlock for access to all 20 flashcards in this deck.
Unlock Deck
k this deck
6
Endorsed is one of the seven policy characteristics. Which of the following statements best describes endorsed?
A) The policy is supported by management.
B) The policy is accepted by the organization's employees.
C) The policy is mandatory; compliance is measured; and appropriate sanctions are applied.
D) The policy is regulated by the government.
A) The policy is supported by management.
B) The policy is accepted by the organization's employees.
C) The policy is mandatory; compliance is measured; and appropriate sanctions are applied.
D) The policy is regulated by the government.
Unlock Deck
Unlock for access to all 20 flashcards in this deck.
Unlock Deck
k this deck
7
Which of the following is the outcome of policy review?
A) Retirement or renewal
B) Retirement or reauthorization
C) Renewal or reauthorization
D) None of the above
A) Retirement or renewal
B) Retirement or reauthorization
C) Renewal or reauthorization
D) None of the above
Unlock Deck
Unlock for access to all 20 flashcards in this deck.
Unlock Deck
k this deck
8
How often should policies be reviewed?
A) Monthly
B) Twice a year
C) Annually
D) Never
A) Monthly
B) Twice a year
C) Annually
D) Never
Unlock Deck
Unlock for access to all 20 flashcards in this deck.
Unlock Deck
k this deck
9
Which of the following statements is not true?
A) Policies should require only what is possible.
B) Policies that are no longer applicable should be retired.
C) All guiding principles and corporate cultures are good.
D) Guiding principles set the tone for a corporate culture.
A) Policies should require only what is possible.
B) Policies that are no longer applicable should be retired.
C) All guiding principles and corporate cultures are good.
D) Guiding principles set the tone for a corporate culture.
Unlock Deck
Unlock for access to all 20 flashcards in this deck.
Unlock Deck
k this deck
10
Which of the following is not one of the tasks of the policy development phase?
A) Approve
B) Write
C) Communicate
D) Authorize
A) Approve
B) Write
C) Communicate
D) Authorize
Unlock Deck
Unlock for access to all 20 flashcards in this deck.
Unlock Deck
k this deck
11
The United States Department of Homeland Security defines how many critical infrastructure sectors?
A) 16
B) 14
C) 20
D) 17
A) 16
B) 14
C) 20
D) 17
Unlock Deck
Unlock for access to all 20 flashcards in this deck.
Unlock Deck
k this deck
12
Which of the following is the seminal tool used to protect both our critical infrastructure and our individual liberties?
A) Information security
B) Society
C) Physical security
D) Policy
A) Information security
B) Society
C) Physical security
D) Policy
Unlock Deck
Unlock for access to all 20 flashcards in this deck.
Unlock Deck
k this deck
13
Which of the following can be defined as the shared attitudes, goals, and practices that characterize a company, corporation, or institution?
A) Regulations
B) Corporate culture
C) Cybersecurity policy
D) Guiding principles
A) Regulations
B) Corporate culture
C) Cybersecurity policy
D) Guiding principles
Unlock Deck
Unlock for access to all 20 flashcards in this deck.
Unlock Deck
k this deck
14
Which of the following is a collection of articles and amendments that provide a framework for the American government and define citizens' rights?
A) The Constitution
B) The Torah
C) Data Protection Act
D) Consumer Credit Act
A) The Constitution
B) The Torah
C) Data Protection Act
D) Consumer Credit Act
Unlock Deck
Unlock for access to all 20 flashcards in this deck.
Unlock Deck
k this deck
15
Which layer in the defense-in-depth strategy includes firewalls, IDS/IPS devices, segmentation, and VLANs?
A) Physical security
B) Network security
C) Perimeter security
D) Application security
A) Physical security
B) Network security
C) Perimeter security
D) Application security
Unlock Deck
Unlock for access to all 20 flashcards in this deck.
Unlock Deck
k this deck
16
Which of the following is another term for statutory law?
A) Legislation
B) Regulation
C) Policy
D) Governance
A) Legislation
B) Regulation
C) Policy
D) Governance
Unlock Deck
Unlock for access to all 20 flashcards in this deck.
Unlock Deck
k this deck
17
Which of the following federal legislations, also known as the Financial Modernization Act of 1999, was created to reform and modernize the banking industry by eliminating existing barriers between banking and commerce?
A) HITECH
B) HIPAA
C) FERPA
D) GLBA
A) HITECH
B) HIPAA
C) FERPA
D) GLBA
Unlock Deck
Unlock for access to all 20 flashcards in this deck.
Unlock Deck
k this deck
18
Which major regulation entity within the European Union (EU) was created to maintain a single standard for data protection among all member states in the EU?
A) Directive on Security of Network and Information Systems (the NIS Directive)
B) EU General Data Protection Regulation (GDPR)
C) European Union Agency for Network and Information Security (ENISA)
D) The Consumer Credit Regulations 2010
A) Directive on Security of Network and Information Systems (the NIS Directive)
B) EU General Data Protection Regulation (GDPR)
C) European Union Agency for Network and Information Security (ENISA)
D) The Consumer Credit Regulations 2010
Unlock Deck
Unlock for access to all 20 flashcards in this deck.
Unlock Deck
k this deck
19
Which key task in the policy development phase requires the authors to consult with internal and external experts, including legal counsel, human resources, compliance, cybersecurity and technology professionals, auditors, and regulators?
A) Writing
B) Authorizing
C) Vetting
D) Planning
A) Writing
B) Authorizing
C) Vetting
D) Planning
Unlock Deck
Unlock for access to all 20 flashcards in this deck.
Unlock Deck
k this deck
20
Which key task in the policy adoption phase is the busiest and most challenging task of all?
A) Implementation
B) Enforcement
C) Monitoring
D) Education
A) Implementation
B) Enforcement
C) Monitoring
D) Education
Unlock Deck
Unlock for access to all 20 flashcards in this deck.
Unlock Deck
k this deck