4. Two examples of security best practices include: “Decision paper on use of screen warning banner”,
and “Sample warning banner from the NLRB”. Under which best security practice area do these two
examples fall?
identification and authentication
5. Problems with benchmarking include all but which of the following?
Organizations don’t often share information on successful attacks
Organizations being benchmarked are seldom identical
Recommended practices change and evolve, thus past performance is no indicator of
future success
Benchmarking doesn’t help in determining the desired outcome of the security process
6. Which of the following is NOT a question to be used as a self-assessment for recommended security
practices in the category of people?
Do you perform background checks on all
employees with access to sensitive data,
areas, or access points?
Would the typical employee recognize a
security issue?
Are the user accounts of former
employees immediately removed on
termination?
Would the typical employee know how to
report a security issue to the right people?
7. Which of the following terms is described as the process of designing, implementing, and managing
the use of the collected data elements to determine the effectiveness of the overall security program?
standards of due care/diligence
8. Which of the following is NOT one of the three types of performance measures used by organizations?
Those that determine the effectiveness of the execution of InfoSec policy
Those that determine the effectiveness and/or efficiency of the delivery of InfoSec
services
Those that evaluate the compliance of non-security personnel in adhering to InfoSec
policy
Those that assess the impact of an incident or other security event on the organization
or its mission
9. Organizations must consider all but which of the following during development and implementation of
an InfoSec measurement program?
Measurements must yield quantifiable information
Data that supports the measures needs to be readily obtainable
Only repeatable InfoSec processes should be considered for measurement
Measurements must be useful for tracking non-compliance by internal personnel