Question 126
Scenario: An organization has recently appointed a CISO. This is a new role in the organization and it signals the increasing need to address security consistently at the enterprise level. This new CISO, while confident with skills and experience, is constantly on the defensive and is unable to advance the IT security centric agenda.
From an Information Security Leadership perspective, which of the following is a MAJOR concern about the CISO's approach to security?
From an Information Security Leadership perspective, which of the following is a MAJOR concern about the CISO's approach to security?
Question 127
What is a difference from the list below between quantitative and qualitative Risk Assessment?
Question 128
Scenario: You are the CISO and are required to brief the C-level executive team on your information security audit for the year. During your review of the audit findings you discover that many of the controls that were put in place the previous year to correct some of the findings are not performing as needed. You have thirty days until the briefing.
To formulate a remediation plan for the non-performing controls what other document do you need to review before adjusting the controls?
To formulate a remediation plan for the non-performing controls what other document do you need to review before adjusting the controls?
Question 129
When you develop your audit remediation plan what is the MOST important criteria?
Question 130
Which of the following is considered the MOST effective tool against social engineering?
