Podcast
Questions and Answers
What is IT Security Management?
What is IT Security Management?
- A process used to achieve and maintain the confidentiality, integrity and availability of an organization’s data, information and IT services. (correct)
- A process used to achieve and maintain the confidentiality, integrity and availability of an organization’s financial assets.
- A process used to achieve and maintain the confidentiality, integrity and availability of an organization’s physical assets
- A process used to achieve and maintain the confidentiality, integrity and availability of an organization’s human resources.
Which of the following is not an IT security management function?
Which of the following is not an IT security management function?
- Determining organizational IT security objectives, strategies and policies
- Identifying and analyzing security threats to IT assets
- Implementing and maintaining a security awareness program
- Developing and implementing a disaster recovery plan (correct)
Who should be accountable for the protection of information assets in an organization?
Who should be accountable for the protection of information assets in an organization?
- The IT department
- The CEO
- The owners of the assets (correct)
- The government
What is the purpose of an IT Audit?
What is the purpose of an IT Audit?
What is the goal of an Information Security Policy?
What is the goal of an Information Security Policy?
What is the first step in the model process for managing information security according to ISO 27001:2013?
What is the first step in the model process for managing information security according to ISO 27001:2013?
What is the purpose of the "Check" step in the model process for managing information security according to ISO 27001:2013?
What is the purpose of the "Check" step in the model process for managing information security according to ISO 27001:2013?
What is the first step in the Risk Assessment process?
What is the first step in the Risk Assessment process?
What is the difference between Qualitative and Quantitative Risk Analysis?
What is the difference between Qualitative and Quantitative Risk Analysis?
What is ISO 27001:2013?
What is ISO 27001:2013?