When establishing metrics for an information security program, the BEST approach is to identify indicators that:
Which of the following is MOST helpful in determining an organization ' s current capacity to mitigate risks?
Which of the following BEST enables an organization to enhance its incident response plan processes and procedures?
Which of the following is a PRIMARY function of an incident response team?
Which of the following is the MOST effective way to detect security incidents?
An organization is performing due diligence when selecting a third party. Which of the following is MOST helpful to reduce the risk of unauthorized sharing of information during this process?
Which of the following presents the GREATEST challenge to the recovery of critical systems and data following a ransomware incident?
Which of the following is MOST important to complete during the recovery phase of an incident response process before bringing affected systems back online?
Which of the following is the MOST important reason to document information security incidents that are reported across the organization?
Several critical systems have been compromised with malware. Which of the following is the BEST strategy to eradicate this incident?
An external security audit has reported multiple instances of control noncompliance. Which of the following is MOST important for the information security manager to communicate to senior management?
Which of the following should be an information security manager s MOST important consideration when determining the priority for implementing security controls?
Which of the following is the PRIMARY responsibility of an information security manager in an organization that is implementing the use of company-owned mobile devices in its operations?
An information security manager has been made aware of a new data protection regulation that will soon go into effect. Which of the following is the BEST way to manage the risk of noncompliance?
What is the PRIMARY role of the information security program?
Which of the following is MOST important to include in a report to key stakeholders regarding the effectiveness of an information security program?
A data loss prevention (DLP) tool has flagged personally identifiable information (Pll) during transmission. Which of the following should the information security manager do FIRST?
Which of the following BEST minimizes information security risk in deploying applications to the production environment?
Which of the following has the GREATEST influence on the successful integration of information security within the business?
During an information security audit, it was determined that IT staff did not follow the established standard when configuring and managing IT systems. Which of the following is the BEST way to prevent future occurrences?