206. Regarding information security governance, which of the following does
a.
Programsb.
Assetsc.
Missiond.
Practices207. What is the most important objective of system security planning?
a.
To improve the protection of information system resourcesb.
To protect highly sensitive systemsc.
To protect highly critical systemsd.
To focus on accredited systems208. Which of the following policy types is usually broad in scope and function?
a.
Program policiesb.
Issue-specific policiesc.
System-specific policiesd.
Network policies209. Which of the following is
a.
Nondisclosure agreementsb.
Rules-of-behavior agreementsc.
Employment agreementsd.
Conflict-of-interest agreements210. Which of the following linkages provide a high-level focus?
a.
Link information security metrics to the organization strategic goalsb.
Link information security metrics to the organization strategic objectivesc.
Link information security activities to the organization-level strategic planningd.
Link information security metrics to the information security program performance211. Which of the following IT security metrics focuses on implementation?
a.
Percentage of system users that have received basic awareness trainingb.
Percentage of operational systems that have completed certification and accreditation following major changesc.
Percentage of new systems that completed certification and accreditation prior to the implementationd.
Percentage of systems successfully addressed in the testing of the contingency planImplementation metrics measure the results of implementation of security policies, procedures, and controls (i.e., demonstrates progress in implementation efforts). Effectiveness/efficiency metrics measure the results of security services delivery (i.e., monitors the results of security controls implementation).
212. Which of the following IT security metrics focuses on efficiency?
a.
Percentage of systems successfully testing the contingency plan at the alternative processing siteb.
Percentage of systems that use automated tools to validate performance of periodic maintenancec.
Percentage of individuals screened before being granted access to organizational information and information systemsd.
Percentage of system components that undergo maintenance on schedule