Chapter 07 – Security Management Practices
TRUE/FALSE
1. Using a practice called benchmarking, you are able to develop an acceptable use policy based on the
typical practices of the industry in which you are working.
2. A company deemed to be using ‘best security practices’ establishes high-quality security in every area
of their security program.
3. One question you should ask when choosing among recommended practices is “Can your organization
afford to implement the recommended practice?”
4. The first phase in the NIST performance measurement process is to identify and document
InfoSec performance goals and objectives.
5. Attaining certification in security management is a long and difficult process, but once attained, an
organization remains certified for the life of the organization.
MULTIPLE CHOICE
1. Creating a blueprint by looking at the paths taken by organizations similar to the one whose plan you
are developing is known as which of the following?
a.
benchmarking
c.
baselining
b.
best practices
d.
due diligence
2. Which of the following is a possible result of failure to establish and maintain standards of due care
and due diligence?
a.
criminal proceedings
c.
chapter 11 filings
b.
legal liability
d.
certification revocation
3. Which of the following is NOT a consideration when selecting recommended best practices?
a.
threat environment is similar
c.
organization structure is similar
b.
resource expenditures are practical
d.
product or service is the same
4. Two examples of security best practices include: “Decision paper on use of screen warning banner”,
and “Sample warning banner from the NLRB”. Under which best security practice area do these two
examples fall?
a.
policy and procedures
c.
logical access controls
b.
personnel security
d.
identification and authentication
5. Problems with benchmarking include all but which of the following?
a.
Organizations don’t often share information on successful attacks
b.
Organizations being benchmarked are seldom identical
c.
Recommended practices change and evolve, thus past performance is no indicator of
future success
d.
Benchmarking doesn’t help in determining the desired outcome of the security process
6. Which of the following is NOT a question to be used as a self-assessment for recommended security
practices in the category of people?
a.
Do you perform background checks on all
employees with access to sensitive data,
areas, or access points?
c.
Would the typical employee recognize a
security issue?
b.
Are the user accounts of former
employees immediately removed on
termination?
d.
Would the typical employee know how to
report a security issue to the right people?
7. Which of the following terms is described as the process of designing, implementing, and managing
the use of the collected data elements to determine the effectiveness of the overall security program?
a.
performance management
c.
best practices
b.
baselining
d.
standards of due care/diligence
8. Which of the following is NOT one of the three types of performance measures used by organizations?
a.
Those that determine the effectiveness of the execution of InfoSec policy
b.
Those that determine the effectiveness and/or efficiency of the delivery of InfoSec
services
c.
Those that evaluate the compliance of non-security personnel in adhering to InfoSec
policy
d.
Those that assess the impact of an incident or other security event on the organization
or its mission
9. Organizations must consider all but which of the following during development and implementation of
an InfoSec measurement program?
a.
Measurements must yield quantifiable information
b.
Data that supports the measures needs to be readily obtainable
c.
Only repeatable InfoSec processes should be considered for measurement
d.
Measurements must be useful for tracking non-compliance by internal personnel
10. Which of the following is NOT a factor critical to the success of an information security performance
program?
a.
Strong upper level management support
b.
High level of employee buy-in to performance measurements
c.
Quantifiable performance measurements
d.
Results oriented measurement analysis
11. Which of the following is NOT a question a CISO should be prepared to answer, about a performance
measures program, according to Kovacich?
a.
Why should these measurements be collected?
b.
Where will these measurements be collected?
c.
What affect will measurement collection have on efficiency?
d.
Who will collect these measurements?
12. In which phase of the NIST performance measures development process will the organization identify
and document the InfoSec performance goals and objectives?
a.
Phase 1
c.
Phase 3
b.
Phase 2
d.
Phase 4
13. InfoSec measurements collected from production statistics depend greatly on which of the following
factors?
a.
types of performance measures developed
b.
number of systems and users of those systems
c.
number of monitored threats and attacks
d.
activities and goals implemented by the business unit
14. Which of the following InfoSec measurement specifications makes it possible to define success in the
security program?
a.
development approach
c.
prioritization and selection
b.
establishing targets
d.
measurements templates
15. Which of the following is the first phase in the NIST process for performance measurement
implementation?
a.
Develop the business case
c.
Prepare for data collection
b.
Obtain resources
d.
Identify corrective actions
16. Which of the following is the last phase in the NIST process for performance measures
implementation?
a.
Apply corrective actions
c.
Document the process
b.
Obtain resources
d.
Develop the business case
17. In security management, which of the following is issued by a management official and serves as a
means of assuring that systems are of adequate quality?
a.
accreditation
c.
performance measurement
b.
certification
d.
testimonial
18. Which of the following is Tier 3 (indicating tactical risk) of the tiered risk management approach?
a.
mission/business process
b.
information system
c.
accounting/logistics
d.
organization
19. According to NIST SP 800-37, which of the following is the first step in the security controls selection
process?
a.
categorize the information system and the information processed
b.
select an initial set of baseline security controls
c.
assess the security controls using appropriate assessment procedures
d.
authorize information system operation based on risk determination
20. The Authorize step of the NIST six-step approach to the risk management framework involves all but
which of the following tasks?
a.
prepare the plan of action and develop
milestones
c.
determine if the cost/benefit ratio is
acceptable
b.
assemble the security authorization
package
d.
determine the risk to organizational
operations
COMPLETION
1. Best security practices balance the need for user _____________ to information with the need for
adequate protection while simultaneously demonstrating fiscal responsibility.
2. A practice related to benchmarking is ____________, which is a measurement against a prior
assessment or an internal goal.
3. ____________________ encompasses a requirement that the implemented standards continue to
provide the required level of protection.
4. A goal of 100 percent employee InfoSec training as an objective for the training program is an
example of a performance __________.
5. The last phase in the NIST performance measures implementation process is to apply
______________ actions which closes the gap found in Phase 2.
MATCHING
a.
accreditation
f.
gold standard
b.
baseline
g.
recommended business practices
c.
benchmarking
h.
standard of due care
d.
certification
i.
best security practices
e.
due diligence
j.
NIST SP 800-37
1. the actions that demonstrate that an organization has made a valid effort to protect others
2. authorization of an IT system to process, store, or transmit information
3. adopting minimum levels of security to establish a future legal defense
4. a model level of performance that demonstrates industrial leadership, quality, and concern for the
protection of information
5. the comprehensive evaluation of the technical and nontechnical security controls of an IT system
6. security efforts that balance the need for information access with the need for adequate protection
7. creating a blueprint by looking at the paths taken by organizations similar to the one whose plan you
are developing
8. a common approach to a Risk Management Framework (RMF) for InfoSec practice
9. procedures that provide a superior level of security for an organization’s information
10. a value or profile of a performance metric against which changes in the performance metric can be
usefully compared
SHORT ANSWER
1. When choosing from among recommended practices, an organization should consider a number of
questions. List four.
2. List the four factors critical to the success of an iInfoSec performance program, according to NIST SP
800-55.
3. Before beginning the process of designing, collecting, and using measures, the CISO should be
prepared to answer the following questions posed by Kovacich. List four of these questions.
4. The process of implementing a performance measures program recommended by NIST involves six
phases. List and describe them.
5. What are the two major activities into which the InfoSec measurement development process
recommended by NIST is divided?
1. Identification and definition of the current InfoSec program
2. Development and selection of specific measurements to gauge the implementation, effectiveness,
efficiency, and impact of the security controls
6. On what do measurements collected from production statistics greatly depend? Explain your answer.
7. Why it measurement prioritization and selection important? How can it be achieved?
8. Why must you do more than simply list the InfoSec measurements collected when reporting them?
Explain.
9. Compare and contrast accreditation and certification.
10. Describe the three tier approach of the RMF as defined by NIST SP 80037.