Question 76

Which of the following metrics would provide management with the MOST useful information about the effectiveness of a security awareness program?
  • Question 77

    The chief information security officer (CISO) should ideally have a direct reporting relationship to the:
  • Question 78

    The PRIMARY objective of a risk management program is to:
  • Question 79

    What is the BEST course of action when an information security manager finds an external service provider has not implemented adequate controls for safeguarding the organization's critical data?
  • Question 80

    When a critical incident cannot be contained in a timely manner and the affected system needs to be taken offline, which of the following stakeholders MUST receive priority communication?