Filters
Question type

Study Flashcards

The ____________________ layer is the place where threats from public networks meet the organization's networking infrastructure in the bull's-eye model.

Correct Answer

verifed

verified

Policies must also specify the penalties for unacceptable behavior and define a(n) ____.


A) appeals process
B) legal recourse
C) responsible managers
D) requirements for revision

E) B) and C)
F) A) and D)

Correct Answer

verifed

verified

According to Confucius,"Tell me,and I forget; show me,and I remember; let me do and I ____."


A) can be held accountable
B) transcend
C) understand
D) can do

E) A) and C)
F) C) and D)

Correct Answer

verifed

verified

Typically,the information security policy administrator is ____.


A) the CEO
B) the COO
C) a mid-level staff member
D) the CIO

E) A) and C)
F) B) and C)

Correct Answer

verifed

verified

Information security policies do not require a champion.

A) True
B) False

Correct Answer

verifed

verified

To ensure ____,an organization must demonstrate that it is continuously attempting to meet the requirements of the market in which it operates.


A) policy administration
B) due diligence
C) adequate security measures
D) certification and accreditation

E) B) and C)
F) B) and D)

Correct Answer

verifed

verified

A(n)____________________ screen is an acknowledgment screen that does not require any unusual action on the part of the user to move past the screen.

Correct Answer

verifed

verified

The Prohibited Usage of Equipment section of the ISSP specifies the penalties and repercussions of violating the usage and systems management policies._________________________

A) True
B) False

Correct Answer

verifed

verified

A risk assessment is performed during the ____ phase of the SecSDLC.


A) implementation
B) analysis
C) design
D) investigation

E) All of the above
F) C) and D)

Correct Answer

verifed

verified

For most corporate documents,a score of ____ is preferred as a Flesch-Kincaid Grade Level score.


A) 4.0 to 5.0
B) 7.0 to 8.0
C) 9.0 to 10.0
D) 11.0 to 12.0

E) All of the above
F) C) and D)

Correct Answer

verifed

verified

A policy should be "signed into law" by a high-level manager before the collection and review of employee input.

A) True
B) False

Correct Answer

verifed

verified

Information security is defined in the ____ component of an EISP.


A) Information Technology Security Responsibilities and Roles
B) Information Technology Security Elements
C) Need for Information Technology Security
D) Reference to Other Information Technology Standards and Guidelines

E) A) and D)
F) A) and C)

Correct Answer

verifed

verified

The three types of information security policies include enterprise information security program policy,issue-specific security policies,and ____________________ security policies.

Correct Answer

verifed

verified

An organization may include a set of disclaimers in the ____ section of the ISSP.


A) Authorized Access and Usage of Equipment
B) Policy Review and Modification
C) Prohibited Usage of Equipment
D) Limitations of Liability

E) None of the above
F) A) and B)

Correct Answer

verifed

verified

When more than two audiences are to be addressed by separate policy documents,it is recommended that a(n)____________________ be prepared before actually writing the first draft policy documents.

Correct Answer

verifed

verified

In the modular approach to creating the ISSP,each of the modules is created and updated by the individuals who are responsible for a specific issue.

A) True
B) False

Correct Answer

verifed

verified

Access control lists can be used to control access to file storage systems.

A) True
B) False

Correct Answer

verifed

verified

____ are used to create procedures.


A) Guidelines
B) Standards
C) Practices
D) Profiles

E) A) and B)
F) All of the above

Correct Answer

verifed

verified

Which of the following would not necessarily be a good reference or resource in writing good policy documents from scratch?


A) The Web
B) A government site
C) A public bookstore
D) Professional literature

E) A) and D)
F) B) and C)

Correct Answer

verifed

verified

A detailed outline of the scope of the policy development project is created during the ____ phase of the SecSDLC.


A) design
B) analysis
C) implementation
D) investigation

E) A) and D)
F) B) and D)

Correct Answer

verifed

verified

Showing 21 - 40 of 133

Related Exams

Show Answer