Services
Discover
Homeschooling
Ask a Question
Log in
Sign up
Filters
Done
Question type:
Essay
Multiple Choice
Short Answer
True False
Matching
Topic
Business
Study Set
Management of Information Security
Quiz 7: Security Management Practices
Path 4
Access For Free
Share
All types
Filters
Study Flashcards
Practice Exam
Learn
Question 81
Multiple Choice
Which of the following is NOT a question you should ask when considering best practices for your organization?
Question 82
Short Answer
A(n)____________________ is an external "value or profile of a performance metric against which changes in the performance metric can be usefully compared."
Question 83
Short Answer
Organizations that adopt minimum levels of security to establish a future legal defense may need to verify that they have done what any ____________________ organization would do in similar circumstances.
Question 84
Short Answer
One of the factors critical to the success of an information security performance program is practical information security ____________________ and procedures.
Question 85
Multiple Choice
Security Certification & Accreditation initiative offers several benefits.Which of the following is NOT one of them?
Question 86
Multiple Choice
Which of the following would NOT be a valuable performance measure?
Question 87
Multiple Choice
Which of the following is NOT a goal of the NIST System Certification and Accreditation Project:
Question 88
Multiple Choice
Under the NIST SP 800-37 security controls model,systems are classified into a specific security certification level.Which of the following is the level of certification for high-priority systems?
Question 89
Short Answer
Best security practices balance the need for information ____________________ with the need for adequate protection while simultaneously demonstrating fiscal responsibility.
Question 90
Short Answer
The benefits of using information security performance measures include "increasing ____________________ for information security performance; improving effectiveness of information security activities; demonstrating compliance with laws,rules,and regulations; and providing quantifiable inputs for resource allocation decisions."
Question 91
Short Answer
A problem with benchmarking is that recommended practices are a(n)____________________; that is,knowing what happened a few years ago does not necessarily tell you what to do next.
Question 92
Multiple Choice
According to NIST SP 800-37,the first step in the security controls selection process is to ____.
Question 93
Short Answer
The ____________________ standard is a model level of performance that demonstrates industrial leadership,quality,and concern for the protection of information.
Question 94
Short Answer
Organizations typically use three types of performance measures,including those that assess the impact of a(n)____________________ or other security event on the organization or its mission.
Question 95
Multiple Choice
In future certification and accreditation practices,NIST will focus less on certification and accreditation strategies,and more on ____.
Question 96
Short Answer
It is no longer sufficient to simply assert effective information security; an organization must demonstrate that it is taking effective measures in the spirit of ____________________.
Question 97
Multiple Choice
The typical length of certification and/or accreditation is ____.
Question 98
Short Answer
When an organization applies statistical and quantitative forms of mathematical analysis to the data points collected to measure the activities and outcomes of the InfoSec program,it is using InfoSec ____________________.