Which management groups are responsible for implementing information security to protect the organizations ability to function?
IT management, Senior Management
Which of the following is NOT a significant benefit of information security governance?
All of these are benefits of information security governance
Which of the following is an information security governance responsibility of the organization’s employees?
Implement policy, report security vulnerabilities and breaches
In information security, which of the following is true about managing risk?
Organizations should implement safeguards that balance the trade-off between risk and cost.
How does technology obsolescence constitute a threat to information security? How can an organization protect against it?
It occurs when technology becomes outdated. Planning is the best way to avoid this by planning to update outdated technology in a timely fashion.
What elements must a written GLBA information security program include?
All of the Above
Which of the following are fundamental objectives of information security? A. Availability B. Integrity C. Confidentiality D. All of the above
D. All of the above
6) Which of the following terms means “knowing how to use a computer”? A) information security B) cloud computing C) computer literacy D) computer compatibility E) collaborative thinking
C) computer literacy
Why is information security a management problem? What can management do that technology cannot?
Management need to perform risk assessments and spend hundreds of thousands of dollars to protect the day to day functioning of the organisation. Technology set policy nor fix issues
Information security decisions should involve what three groups?
information security managers/professionals, information technology managers/professionals, non-technical business managers/professionals
