Chapter 01 – Introduction to the Management of Information Security
TRUE/FALSE
1. Corruption of information can occur only while information is being stored.
2. The authorization process takes place before the authentication process.
3. The first step in solving problems is to gather facts and make assumptions.
4. Project scope management ensures that the project plan includes only those activities that are
necessary to complete it.
5. A project can have more than one critical path.
MULTIPLE CHOICE
1. Communications security involves the protection of which of the following?.
a.
radio handsets
c.
the IT department
b.
people, physical assets
d.
media, technology, and content
2. According to the C.I.A. triangle, which of the following is a desirable characteristic for computer
security?
a.
accountability
c.
authorization
b.
availability
d.
authentication
3. Which of the following is a C.I.A. characteristic that ensures that only those with sufficient privileges
and a demonstrated need may access certain information?
a.
Integrity
c.
Authentication
b.
Availability
d.
Confidentiality
4. The use of cryptographic certificates to establish Secure Sockets Layer (SSL) connections is an
example of which process?
a.
accountability
c.
identification
b.
authorization
d.
authentication
5. What do audit logs that track user activity on an information system provide?
a.
identification
c.
accountability
b.
authorization
d.
authentication
6. Which of the following is the process that develops, creates, and implements strategies for the
accomplishment of objectives?
a.
leading
c.
organizing
b.
controlling
d.
planning
7. Which of the following is the principle of management dedicated to the structuring of resources to
support the accomplishment of objectives?
a.
organization
c.
controlling
b.
planning
d.
leading
8. Which of the following is the first step in the problem-solving process?
a.
Analyze and compare the possible solutions
b.
Develop possible solutions
c.
Recognize and define the problem
d.
Select, implement and evaluate a solution
9. Which of the following is NOT a step in the problem-solving process?
a.
Select, implement and evaluate a solution
b.
Analyze and compare possible solutions
c.
Build support among management for the candidate solution
d.
Gather facts and make assumptions
10. Which of the following is NOT a unique function of Information Security Management?
a.
planning
c.
project management
b.
protection
d.
principles
11. Which of the following functions of Information Security Management seeks to dictate certain
behavior within the organization through a set of organizational guidelines?
a.
planning
c.
programs
b.
policy
d.
people
12. Which function of InfoSec Management encompasses security personnel as well as aspects of the
SETA program?
a.
protection
b.
people
c.
projects
d.
policy
13. Information security project managers often follow methodologies based on what methodology
promoted by the Project Management Institute?
a.
The Security Systems Development Life Cycle (SecSDLC)
b.
The Security Project And Management Methodology (SPAMM)
c.
Project Management System Methodology (PMS/Meth)
d.
Project Management Body of Knowledge (PMBoK)
14. Which of the following is NOT a knowledge area in the Project Management knowledge body?
a.
Integration
c.
Scope
b.
Quality
d.
Technology
15. What is one of the most frequently cited failures in project management?
a.
Overly restrictive management
b.
Excessive personnel on project
c.
Failure to meet project deadlines
d.
Loose or ambiguous project specifications
16. The management of human resources must address many complicating factors; which of the following
is NOT among them?
a.
All workers operate at approximately the same level of efficiency
b.
Not all workers begin the project with the same degree of skill
c.
Skill mixtures among the actual project workers seldom match the needs of the project
plan.
d.
Some tasks may require skills that are not available from resources on hand
17. In the WBS approach, the project plan is first broken down into tasks placed on the WBS task list. The
minimum attributes that should be identified for each task include all but which of the following?
a.
Work to be accomplished (activities and deliverables)
b.
Estimated amount of effort required for completion, in hours or workdays
c.
The common or specialized skills needed to perform the task
d.
The number of people and other resources needed for each task
18. Which of the following was originally developed in the late 1950s to meet the need of the rapidly
expanding engineering projects associated with government acquisitions such as weapons systems?
a.
GANTT
c.
CPM
b.
PERT
d.
WBS
19. Using the Program Evaluation and Review Technique, which of the following identifies the sequence
of events or activities that requires the longest duration to complete, and that therefore cannot be
delayed without delaying the entire project?
a.
program path
c.
critical path
b.
critical function
d.
crucial factor set
20. It is possible to take a very complex operation and diagram it in PERT if you can answer three key
questions about each activity. Which of the following is NOT one of them?
a.
How long will it take?
b.
What activity occurs immediately before this activity?
c.
What activity occurs immediate activity after this activity?
d.
What other activities require the same resources as this activity?
COMPLETION
1. The three levels of planning are strategic planning, tactical planning, and ____________________
planning.
2. The set of organizational guidelines that dictates certain behavior within the organization is called
____________________.
3. ____________________ occurs when the quantity or quality of project deliverables is expanded from
the original project plan.
4. If the project deliverables meet the requirements specified in the project plan, the project has met its
____________________ objective.
5. In the PERT technique, the difference in time between the critical path and any other path is called
____________________.
MATCHING
a.
identification
f.
integrity
b.
authentication
g.
project management
c.
scope creep
h.
Operations security
d.
slack time
i.
authorization
e.
information security
j.
organizing
1. the difference between the time needed to complete the critical path and the time needed to arrive at
completion using any other path
2. a mechanism that provides information about a supplicant that wants to be granted access to a known
entity
3. a process for identifying and controlling the resources applied to the project
4. a state that occurs when the quantity or quality of project deliverables is expanded from the original
project plan
5. a process that determines if a user has been specifically and explicitly authorized by the proper
authority to perform a function
6. the protection of information and its critical characteristics
7. the management function dedicated to the structuring of resources to support the accomplishment of
objectives
8. a specialized area of security that encompasses protecting the organization’s ability to carry out its
operational activities without interruption or compromise
9. the process of validating a supplicant’s purported identity, thus ensuring that the entity requesting
access is the entity it claims to be
10. a quality or state of being whole, complete, and uncorrupted
SHORT ANSWER
1. Explain the differences between a leader and a manager.
2. List and explain the critical characteristics of information as defined by the C.I.A. triangle.
3. List and explain the four principles of management under the contemporary or popular management
theory. Briefly define each.
4. List the steps that can be used as a basic blueprint for solving organizational problems.
5. List the advantages and disadvantages of using the Program Evaluation and Review Technique
method?
6. What are the three distinct groups of decision makers or communities of interest on an information
security team?
7. List the four specialized areas of security.
8. List three measures that are commonly used to protect the confidentiality of information.
9. What is authentication? Provide some examples.
10. Discuss the planning element of information security.