Chapter 11: Personnel and Security
TRUE/FALSE
1. InfoSec is a profession with little personnel turnover – most InfoSec professionals stay in their
positions for a very long time.
2. The most common qualification for a CISO includes the CISSP and CISM certifications.
3. Most hiring organizations are aware of the precise value of information security certifications because
these programs have been in existence for a long time.
4. The SSCP certification is more applicable to the security manager than the security technician.
5. Social engineering uses persuasive techniques to gain an individual’s confidence in an effort to obtain
information.
MULTIPLE CHOICE
1. To move the InfoSec discipline forward, organizations should take all but which of the following
steps?
a.
learn more about the requirements and
qualifications for InfoSec and IT positions
c.
insist all mid-level and upper-level
management take introductory InfoSec
courses
b.
learn more about InfoSec budgetary and
personnel needs
d.
grant the InfoSec function an appropriate
level of influence and prestige
2. Employees who create and install security solutions fall under which classification of InfoSec
positions?
a.
definers
c.
builders
b.
administers
d.
analyzers
3. Which of the following is typically true about the CISO position?
a.
business managers first and technologists
second
c.
develop appropriate InfoSec policies,
standards, guidelines, and procedures
b.
accountable for the day-to-day operation
of all or part of the InfoSec program
d.
technically qualified individual who
may configure firewalls and IDPSs
4. Ideally, a candidate for the CISO position should have experience in what other InfoSec position?
a.
security officer
c.
security technician
b.
security consultant
d.
security manager
5. Which of the following InfoSec positions is responsible for the day-to-day operation of the InfoSec
program?
a.
CISO
c.
security officer
b.
security manager
d.
security technician
6. CISO’s should follow six key principles to shape their careers. Which of the following is NOT
among those six principles?
a.
business engagement
c.
relationship management
b.
service delivery
d.
technical excellence
7. Which of the following is NOT a typical task performed by the security technician?
a.
configure firewalls and IDPSs
c.
coordinate with systems and network
administrators
b.
participate in short-term and long-term
planning
d.
specialize in advanced security appliances
8. Which of the following is a responsibility of an information security department manager?
a.
offering technical information security consulting services to network administrators
b.
running vulnerability identification software packages
c.
preparing postmortem analyses of information security breaches
d.
training Access Control System administrators to set up firewalls
9. Which of the following is a responsibility of an InfoSec technician?
a.
developing InfoSec requirements for the organization
b.
providing hands-on technical consulting services to teams of technical specialists
c.
establishing procedures for the identification of information assets
d.
managing the development of InfoSec policies
10. Which of the following job titles with InfoSec elements is part of the IT community of interest?
a.
access control system administrator
c.
physical asset protection specialist
b.
local InfoSec coordinator
d.
help desk specialist
11. Which security certification is considered the most prestigious for security managers and CISOs?
a.
CISSP
c.
SSCP
b.
GIAC
d.
SCP
12. Which of the following is a domain of the CISSP certification?
a.
cryptography
c.
monitoring and analysis
b.
risk, response, and recovery
d.
malicious code and activity
13. Which of the following is NOT a CISSP concentration?
a.
ISSAP
c.
ISSMP
b.
ISACA
d.
ISSEP
14. Which certification program has certifications that require the applicant to complete a written practical
assignment that tests the applicant’s ability to apply skills and knowledge.
a.
GIAC
c.
CRISC
b.
CGEIT
d.
CISA
15. Which of the following is NOT among the areas covered as part of the Certified Computer Examiner
(CCE) certification process?
a.
server hardware construction and theory
b.
general computer hardware used in data collection
c.
ethics in practice
d.
forensics data seizure procedures
16. Before hiring security personnel, which of the following should be conducted before the organization
extends an offer to any candidate, regardless of job level?
a.
new hire orientation
c.
exit interview
b.
covert surveillance
d.
background check
17. Which of the following is NOT a task that must be performed if an employee is terminated?
a.
former employee must return all media
b.
former employee’s home computer must be audited
c.
former employee’s office computer must be secured
d.
former employee should be escorted from the premises
18. Which of the following is NOT a common type of background check that may be performed on a
potential employee?
a.
identity check
c.
motor vehicle records
b.
political activism
d.
drug history
19. Which of the following policies makes it difficult for an individual to violate InfoSec and is quite
useful in monitoring financial affairs?
a.
task rotation
c.
separation of duties
b.
two-man control
d.
job rotation
20. Which of the following policies requires that two individuals review and approve each other’s work
before the task is considered complete?
a.
task rotation
c.
separation of duties
b.
two-person control
d.
job rotation
21. Which of the following policies requires that every employee be able to perform the work of at least
one other staff member?
a.
task rotation
c.
two-man control
b.
job rotation
d.
separation of duties
22. Which of the following is a nontechnical type of attack that is usually subtle?
a.
denial of service
c.
Trojan horse
b.
social engineering
d.
malware
COMPLETION
1. In the classification of information security positions, senior people with a lot of broad knowledge, but
often not a lot of depth, fall under the category of those that ____________________.
2. Ultimately, the _______________________ is the spokesperson for the security team and is
responsible for the overall InfoSec program.
3. It is the responsibility of a _______________________ to develop appropriate InfoSec policies,
standards, guidelines, and procedures.
4. A security ____________________ may have technical responsibilities but his or her role is the
typical information security entry-level position.
5. The CompTIA ____________________ certification tests an individual’s security knowledge mastery
and requires two years on-the-job networking experience, with emphasis on security.
MATCHING
a.
definers
f.
ethics officer
b.
builders
g.
CISSP
c.
security manager
h.
SSCP
d.
security technician
i.
SANS Institute
e.
systems programmer
j.
CCE
1. may configure firewalls and IDPSs
2. focuses on practices, roles, and responsibilities as defined by experts
3. accountable for the day-to-day operation of the InfoSec program
4. computer forensics certification
5. member of the general business community
6. provide the policies, guidelines, and standards
7. considered to be the most prestigious certification for security managers
8. developed a series of technical security certifications
9. create and install security solutions
10. member of the IT community
SHORT ANSWER
1. Briefly describe at least five types of background checks.
2. Briefly describe the two outprocessing methods of handling employees who leave their positions at a
company.
3. Briefly describe the classifications of InfoSec positions as defined by Schwartz et al.
4. What are some of the common qualifications for a CISO?
5. List the six key principles that should shape the career of a CISO.
6. Describe the position of security manager.
7. What are the qualifications and position requirements of a typical security technician?
8. Describe the SSCP certification. How does it compare to the CISSP?
9. Describe the certifications developed by SANS. How are they different from InfoSec certifications
like CISSP and SSCP?
10. What is the Security+ certification and who is a typical candidate for this certification?