Chapter 5: Information Security Program Development
Practice Question Set 1
Q.1
Answer: A. To improve the integration of business and information security processes
Explanation: The most important challenge for a security manager is to obtain support from senior management and other business units for changing the business processes to include the security aspect. As the incident has already happened, business units will be more open to supporting security processes. In the absence of close integration of business and security processes, the other options will not be effective.
Q. 2
Answer: B. To understand the risk of technology and its contribution to security objectives
Explanation: An information security manager is required to evaluate the risk of technology and determine the relevant controls to safeguard IT resources. The other options are secondary aspects.
Q. 3
Answer: C. Strategy
Explanation: An information security strategy is a set of actions...