Question 206

The FIRST step in establishing a security governance program is to:
  • Question 207

    An information security program should be sponsored by:
  • Question 208

    Which of the following presents the GREATEST threat to the security of an enterprise resource planning (ERP) system?
  • Question 209

    As an organization grows, exceptions to information security policies that were not originally specified may become necessary at a later date. In order to ensure effective management of business risks, exceptions to such policies should be:
  • Question 210

    An organization has to comply with recently published industry regulatory requirements - compliance that potentially has high implementation costs. What should the information security manager do FIRST?