Chapter 02 – Planning for Security
TRUE/FALSE
1. Because it sets out general business intentions, a mission statement does not need to be concise.
2. A clearly directed strategy flows from top to bottom rather than from bottom to top.
3. A top-down approach to information security usually begins with a systems administrator’s attempt to
improve the security of their systems.
4. The primary goal of external monitoring is to maintain an informed awareness of the state of all of the
organization’s networks, information systems, and information security defenses.
5. Penetration testing is often conducted by contractors, who are commonly referred to as black-hats.
MULTIPLE CHOICE
1. Which of the following explicitly declares the business of the organization and its intended areas of
operations?
a.
vision statement
c.
mission statement
b.
values statement
d.
business statement
2. Which type of planning is the primary tool in determining the long-term direction taken by an
organization?
a.
strategic
c.
operational
b.
tactical
d.
managerial
3. Which of the following is true about planning?
a.
Strategic plans are used to create tactical plans
b.
Tactical plans are used to create strategic plans
c.
Operational plans are used to create tactical plans
d.
Operational plans are used to create strategic plans
4. In which level of planning are budgeting, resource allocation, and manpower critical components?
a.
strategic
c.
organizational
b.
operational
d.
tactical
5. Which type of planning is used to organize the ongoing, dayto-day performance of tasks?
a.
Strategic
c.
Organizational
b.
Tactical
d.
Operational
6. The basic outcomes of InfoSec governance should include all but which of the following?
a.
Value delivery by optimizing InfoSec investments in support of organizational objectives
b.
Performance measurement by measuring, monitoring, and reporting information security
governance metrics to ensure that organizational objectives are achieved
c.
Time management by aligning resources with personnel schedules and organizational
objectives
d.
Resource management by utilizing information security knowledge and infrastructure
efficiently and effectively
7. The National Association of Corporate Directors (NACD) recommends four essential practices for
boards of directors. Which of the following is NOT one of these recommended practices?
a.
Hold regular meetings with the CIO to discuss tactical InfoSect planning
b.
Assign InfoSec to a key committee and ensure adequate support for that committee
c.
Ensure the effectiveness of the corporation’s InfoSec policy through review and approval
d.
Identify InfoSec leaders, hold them accountable, and ensure support for them
8. Which of the following should be included in an InfoSec governance program?
a.
An InfoSec time management policy
b.
An InfoSec risk management methodology
c.
An InfoSec project management assessment from an outside consultant
d.
All of these are components of the InfoSec governance program
9. According to the Corporate Governance Task Force (CGTF), which phase in the IDEAL model and
framework lays the groundwork for a successful improvement effort?
a.
Initiating
c.
Acting
b.
Establishing
d.
Learning
10. According to the Corporate Governance Task Force (CGTF), during which phase in the IDEAL model
and framework does the organization plan the specifics of how it will reach its destination?
a.
Initiating
c.
Acting
b.
Establishing
d.
Learning
11. Which of the following is an information security governance responsibility of the Chief Security
Officer?
a.
Communicate policies and the program
b.
Set security policy, procedures, programs and training
c.
Brief the board, customers and the public
d.
Implement policy, report security vulnerabilities and breaches
12. Which of the following is a key advantage of the bottom-up approach to security implementation?
a.
strong upper-management support
b.
a clear planning and implementation process
c.
utilizes the technical expertise of the individual administrators
d.
coordinated planning from upper management
13. Which of the following is a key step needed in order for a JAD approach to be successful?
a.
prepare software demonstrations
c.
provide sequence-driven policies
b.
organize workshop activities
d.
use event-driven procedures
14. In which model in the SecSDLC does the work products of each phase fall into the next phase to serve
as its starting point?
a.
continuous
c.
circular
b.
cycle-based
d.
waterfall
15. What is the first phase of the SecSDLC?
a.
analysis
c.
logical design
b.
investigation
d.
physical design
16. In which phase of the SecSDLC does the risk management task occur?
a.
physical design
c.
investigation
b.
implementation
d.
analysis
17. Blackmail threat of informational disclosure is an example of which threat category?
a.
Espionage or trespass
c.
Sabotage or vandalism
b.
Information extortion
d.
Compromises of intellectual property
18. Which of the following is a feature left behind by system designers or maintenance staff that allows
quick access to a system at a later time by bypassing access controls?
a.
brute force
c.
back door
b.
DoS
d.
hoax
19. Which type of attack involves sending a large number of connection or information requests to a
target?
a.
malicious code
c.
brute force
b.
denial-of-service (DoS)
d.
spear fishing
20. Which of the following set the direction and scope of the security process and provide detailed
instruction for its conduct?
a.
system controls
c.
operational controls
b.
technical controls
d.
managerial controls
COMPLETION
1. The impetus to begin an SDLC-based project may be ____________________, that is, a response to
some activity in the business community, inside the organization, or within the ranks of employees,
customers, or other stakeholders.
2. A ____________ overflow is an application error that occurs when the system can’t handle the amount
of data that is sent.
3. A(n) ___________ attack enables an attacker to extract secrets maintained in a security system by
observing the time it takes the system to respond to various queries.
4. _________resources include people, hardware, and the supporting system elements and resources
associated with the management of information in all its states.
5. The ______________________ phase is the last phase of SecSDLC, but perhaps the most important.
6. In ____________________ testing, security personnel simulate or perform specific and controlled
attacks to compromise or disrupt their own systems by exploiting documented vulnerabilities.
MATCHING
a.
attack
f.
risk management
b.
data owner
g.
strategic planning
c.
exploit
h.
operational controls
d.
plan-driven
i.
technical controls
e.
risk assessment
j.
threat agent
1. usually a documented way to circumvent controls or take advantage of weaknesses in control systems
2. the process of moving an organization towards its vision by accomplishing its mission
3. an act that is an intentional or unintentional attempt to compromise the information and/or the systems
that support it
4. assigns a comparative risk rating or score to each specific information asset
5. measures that use or implement a technical solution to reduce risk of loss in an organization
6. individual who determines the level of classification associated with data
7. measures that deal with the functionality of security in an organization
8. associated with assessing risks and then implementing or repairing controls to assure the
confidentiality, integrity, and availability of information
9. a specific instance or component that represents a danger to an organization’s assets
10. the impetus for a project that is the result of a carefully developed planning strategy
SHORT ANSWER
1. Information security governance yields significant benefits. List five.
2. Describe what happens during each phase of the IDEAL General governance framework.
3. There are twelve categories of threats to information security. List five of them and provide an
example of each.
4. What is the role of planning in InfoSec management? What are the factors that affect planning?
5. What is the values statement and what is its importance to an organization?
6. Contrast the vision statement with the mission statement.
7. How does tactical planning differ from strategic planning?
8. According to the ITGI, what are the four supervisory tasks a board of directors should perform to
ensure strategic InfoSec objectives are being met?
9. Describe the key approaches organizations are using to achieve unified ERM.
10. What is necessary for a top-down approach to the implementation of InfoSec to succeed?