Question 1 of 10 · Information Security Governance
Which describes the correct approach to security metrics presented at different levels?
Good metrics reporting shows the same facts to every level, at the resolution each needs, with business consequence brought forward for executives. Different audiences picking different facts, or one report for everyone, breaks either consistency or relevance.
Question 2 of 10 · Information Security Risk Management
Which characteristic makes a key risk indicator useful?
A key risk indicator earns its place when it is tied to a named risk, has an owner, and crosses a defined threshold that triggers a set action. Ease of collection, a good-looking trend or peer comparability do not make it drive decisions.
Question 3 of 10 · Information Security Program
Which is the correct approach to selecting controls for a newly identified risk?
Controls are chosen for the specific risk: what reduces it, whether the reduction is worth the cost, and who will operate the control. Copying a framework's list, a peer's choices or the strongest option ignores fit and cost.
Question 4 of 10 · Incident Management
Who should hold the authority to declare a major incident?
The incident plan names the role that declares a major incident and the criteria it applies, so the decision is fast and consistent. Leaving it to whoever notices first, or pushing it to the chief executive, causes delay or inconsistency.
Question 5 of 10 · Information Security Governance
What is the principal purpose of a security charter?
A security charter gives the function its mandate, authority, scope and reporting line, which is what lets it act across the organisation. Architecture, budget and the policy set are documented elsewhere.
Question 6 of 10 · Information Security Risk Management
Which describes the correct handling of an emerging risk with no historical data?
An emerging risk with no history is assessed with scenario analysis and leading indicators, and the assumptions are written down so the view can be revisited. Excluding it, deferring it or scoring it at maximum by default are all ways of not assessing it.
Question 7 of 10 · Information Security Program
What does a maturity model provide?
A maturity model describes levels of capability, giving people a shared way to say where they are and what the next step looks like. It is not a benchmark of compliance, a control catalogue or a scoring method.
Question 8 of 10 · Incident Management
What determines the deadline for regulatory notification?
The notification deadline comes from the applicable law and contracts, and the clock usually starts when the organisation becomes aware, not when the investigation ends. Internal policy and severity ratings do not change a legal deadline.
Question 9 of 10 · Information Security Governance
Which is the most significant weakness of a policy that cannot be complied with in practice?
A policy nobody can follow teaches people that policies are optional, which undermines every other policy. The extra burden, audit findings and exceptions are symptoms of that deeper damage.
Question 10 of 10 · Information Security Risk Management
Which is the correct first step when establishing risk management in an organisation with no register?
Without criteria, assessments produce results that cannot be compared or acted on.
0 of 10
Information Security Governance
Information Security Risk Management
Information Security Program
Incident Management
Which domains cost you the points? Members see a breakdown by domain and a study plan built from it.