Question 16
Which of the following functions evaluates patches used to close software vulnerabilities and perform validation of new systems to assure compliance with security?
Question 17
The framework that helps to define a minimum standard of protection that business stakeholders must attempt to achieve is referred to as a standard of:
Question 18
SCENARIO: A Chief Information Security Officer (CISO) recently had a third party conduct an audit of the security program. Internal policies and international standards were used as audit baselines. The audit report was presented to the CISO and a variety of high, medium and low rated gaps were identified.
Which of the following is the FIRST action the CISO will perform after receiving the audit report?
Which of the following is the FIRST action the CISO will perform after receiving the audit report?
Question 19
Which of the following functions implements and oversees the use of controls to reduce risk when creating an information security program?
Question 20
Which of the following provides an independent assessment of a vendor's internal security controls and overall posture?
