86) Which of the following laws makes it mandatory for organizations to demonstrate that there
are controls in place to prevent misuse and detect any potential problems?
A) Sarbanes–Oxley Act
B) Trade Expansion Act of 1962
C) Electronic Communications Privacy Act of 1986
D) Central Intelligence Agency Act
E) U.S.A. Patriot Act
Difficulty: Easy
Learning Obj.: 10.3: Discuss the process of managing IS security and describe various IS
controls that can help in ensuring IS security.
Classification: Concept
87) The ________ is a set of best practices that helps organizations to maximize the benefits
from their IS infrastructure and to establish appropriate controls.
A) Sarbanes–Oxley Act of 2002 (S-OX)
B) Completely Automated Public Turing Test to Tell Computers and Humans Apart (CAPTCHA)
C) Electronic Communications Privacy Act of 1986
D) control objectives for information and related technology (COBIT)
E) USA Patriot Act
Difficulty: Easy
Learning Obj.: 10.3: Discuss the process of managing IS security and describe various IS
controls that can help in ensuring IS security.
Classification: Concept
88) Insuring all the systems and information processing tasks is an essential part of risk
acceptance strategy.
Difficulty: Easy
Learning Obj.: 10.3: Discuss the process of managing IS security and describe various IS
controls that can help in ensuring IS security.
Classification: Concept
89) A virtual private network is also called a secure tunnel.
Difficulty: Easy
Learning Obj.: 10.3: Discuss the process of managing IS security and describe various IS
controls that can help in ensuring IS security.
Classification: Concept
28