Question 776

FISMA requires federal agencies to protect IT systems and data. How often should compliance be audited by an external organization?
  • Question 777

    An organization with a large number of applications wants to establish a security risk assessment program.
    Which of the following would provide the MOST useful information when determining the frequency of risk assessments?
  • Question 778

    Which group has PRIMARY ownership of reputational risk stemming from unethical behavior within the organization?
  • Question 779

    If preventive controls cannot be Implemented due to technology limitations, which of the following should be done FIRST to reduce risk7
  • Question 780

    The PRIMARY basis for selecting a security control is: