Question 16

Which of the following functions evaluates patches used to close software vulnerabilities and perform validation of new systems to assure compliance with security?
  • Question 17

    The framework that helps to define a minimum standard of protection that business stakeholders must attempt to achieve is referred to as a standard of:
  • Question 18

    SCENARIO: A Chief Information Security Officer (CISO) recently had a third party conduct an audit of the security program. Internal policies and international standards were used as audit baselines. The audit report was presented to the CISO and a variety of high, medium and low rated gaps were identified.
    Which of the following is the FIRST action the CISO will perform after receiving the audit report?
  • Question 19

    Which of the following functions implements and oversees the use of controls to reduce risk when creating an information security program?
  • Question 20

    Which of the following provides an independent assessment of a vendor's internal security controls and overall posture?