5. Which type of planning is used to organize the ongoing, day–to-day performance of tasks?
6. The basic outcomes of InfoSec governance should include all but which of the following?
Value delivery by optimizing InfoSec investments in support of organizational objectives
Performance measurement by measuring, monitoring, and reporting information security
governance metrics to ensure that organizational objectives are achieved
Time management by aligning resources with personnel schedules and organizational
objectives
Resource management by utilizing information security knowledge and infrastructure
efficiently and effectively
7. The National Association of Corporate Directors (NACD) recommends four essential practices for
boards of directors. Which of the following is NOT one of these recommended practices?
Hold regular meetings with the CIO to discuss tactical InfoSect planning
Assign InfoSec to a key committee and ensure adequate support for that committee
Ensure the effectiveness of the corporation’s InfoSec policy through review and approval
Identify InfoSec leaders, hold them accountable, and ensure support for them
8. Which of the following should be included in an InfoSec governance program?
An InfoSec time management policy
An InfoSec risk management methodology
An InfoSec project management assessment from an outside consultant
All of these are components of the InfoSec governance program
9. According to the Corporate Governance Task Force (CGTF), which phase in the IDEAL model and
framework lays the groundwork for a successful improvement effort?
10. According to the Corporate Governance Task Force (CGTF), during which phase in the IDEAL model
and framework does the organization plan the specifics of how it will reach its destination?
11. Which of the following is an information security governance responsibility of the Chief Security
Officer?
Communicate policies and the program
Set security policy, procedures, programs and training
Brief the board, customers and the public