MoIS4 Ch11 Review Questions
1. When an organization undertakes an InfoSec-driven review of job descriptions, which job
descriptions must be reviewed? Which IT jobs not directly associated with information
security should be reviewed?
2. List and describe the criteria for selecting InfoSec personnel.
When selecting InfoSec personnel, candidates should be sought who understand the
3. What are some of the factors that influence an organization’s hiring decisions?
One factor that may influence an organizations hiring decisions is whether the person
4. What attributes do organizations seek in a candidate when hiring InfoSec professionals?
Prioritize this list of attributes and justify your ranking.
When hiring, organizations seek to employ those with experience, with applicable
5. What are the critical actions that management must consider taking when dismissing an
employee? Do these issues change based on whether the departure is friendly or hostile?
When dismissing an employee, management must perform the following actions:
The former employees access to the organizations systems must be disabled.
6. How do the security considerations for temporary or contract workers differ from those
for regular employees?
For security purposes, the information access given to temporary and contract employees
7. Which two career paths are the most commonly encountered as entrees into the InfoSec
discipline? Are there other paths? If so, describe them.
The two career paths that often serve as entrees into information security are military/law
8. Why is it important to have a body of standard job descriptions for hiring InfoSec
professionals?
It is important to have a body of standard job descriptions when hiring InfoSec
9. What functions does the CISO perform, and what are the key qualifications and
requirements for the position?
The CISO is responsible for all security functions within an organization. He or she is
10. What functions does the security manager perform, and what are the key qualifications
and requirements for the position?
A security manager is responsible for the daytoday activities involved with security.
11. What functions does the security technician perform, and what are the key qualifications
and requirements for the position?
A security technician is a technically qualified individual who configures firewalls and
IDSs, implements security software, diagnoses and troubleshoots problems, and
12. What functions does the internal security consultant perform, and what are the key
qualifications and requirements for the position?
The internal security consultant performs many tasks, but the main task is to give
13. What is the rationale for acquiring professional credentials?
The rationale for acquiring professional credentials is that it is what companies mainly
14. List and describe the certification credentials available to InfoSec professionals.
Certifications available to InfoSec practitioners include: CISSP, SSCP, GIAC, SCP,
Security+, CISA, CISM, and CCE.
15. In your opinion, who should pay for the expenses of certification? Under what
circumstances would your answer be different? Why?
[Individual student responses will vary; the following is one possible answer.] An
employer should pay for certifications when they are required or could add a benefit for
16. List and describe the standard personnel practices that are part of the InfoSec function.
What happens to these practices when they are integrated with InfoSec concepts?
Information security personnel should understand how organizations are structured and
operate, recognize that information security is a management task that cannot be handled
17. Why shouldn’t you show a job candidate secure areas during interviews?
Candidates should not be given unrestricted access since the individual could observe
18. List and describe the types of nonemployee workers often used by organizations. What
special security considerations apply to such workers, and why are they significant?
Organizations use nonemployees such as temps, contract workers, consultants and
business partners. Temps are workers who are hired to fill a temporary position. Contract
19. What is separation of duties? How can this method be used to improve an organization’s
InfoSec practices?
Separation of duties is a way of assigning multiple people to a process to provide checks
20. What is least privilege? Why is implementing least privilege important?
Least privilege is allowing employees to access only the information resources they need