Prior to implementing a bring your own device (BYOD) program, it is MOST important to:
To inform a risk treatment decision, which of the following should the information security manager compare with the organization ' s risk appetite?
Which of the following is the BEST approach for data owners to use when defining access privileges for users?
Define access privileges based on user roles.
Adopt user account settings recommended by the vendor.
Perform a risk assessment of the users ' access privileges.
Which of the following BEST enables the design of an effective incident escalation process?
An organization has recently purchased cybersecurity insurance after the board voiced concern about the potential for a security breach. With this response to the perceived risk, the organization:
A security review identifies that confidential information on the file server has been accessed by unauthorized users in the organization. Which of the following should the information security manager do FIRST?
Which of the following roles is BEST able to influence the security culture within an organization?
Which of the following is the MOST important consideration when attempting to create a security-focused culture?
Which of the following is the BEST strategy when determining an organization’s approach to risk treatment?
Which of the following is the BEST way to monitor the effectiveness of security controls?
Once a suite of security controls has been successfully implemented for an organization ' s business units, it is MOST important for the information security manager to:
Which of the following would provide the MOST value to senior management when presenting the results of a risk assessment?
Which of the following is the BEST approach for addressing noncompliance with security standards?
Which of the following BEST helps to ensure a risk response plan will be developed and executed in a timely manner?
An organization wants to integrate information security into its HR management processes. Which of the following should be the FIRST step?
Which of the following is the responsibility of a risk owner?
Which of the following is the MOST important consideration when planning to implement artificial intelligence to enhance an organization’s vulnerability and control deficiency analysis capabilities?
Which of the following is the PRIMARY objective of the incident management recovery phase?
Which of the following will BEST facilitate the integration of information security governance into enterprise governance?
Which of the following has the GREATEST impact on the ability to successfully execute a disaster recovery plan (DRP)?