MoIS4 CH02 Review Questions
1. What is planning? How does an organization determine if planning is necessary?
Answer: Planning is the preparation, application, and control of a sequence of action steps to achieve
2. What are the three common levels of planning?
Answer: Tactical planningTactical planning has a shorter focus than strategic planning, usually one to
3. Who are stakeholders? Why is it important to consider their views when planning?
Answer: Stakeholders are people who will gain or lose (usually money) depending on the success or
4. What is a values statement? What is a vision statement? What is a mission statement?
Why are they important? What do they contain?
Answer: The values statement is an established formal set of organized principles, standards, and qualities
5. What is strategy?
Answer: A strategy is a method to accomplish a specific objective. It often forms the basis for the organization’s
6. What is InfoSec governance?
Answer: InfoSec governance includes all the accountabilities and methods undertaken by a board of directors and
7. What should a board of directors recommend as an organization’s InfoSec objectives?
Answer: 1. Inculcating a culture that recognizes the criticality of information and InfoSec to the
8. What are the five basic outcomes that should be achieved through InfoSec governance?
Answer: 1. Strategic alignment of InfoSec with business strategy to support organizational objectives 2.
9. Describe top-down strategic planning. How does it differ from bottom-up strategic
planning? Which is usually more effective in implementing security in a large, diverse
organization?
Answer: Top-down strategic planning involves high-level managers providing resources and giving
10. How does the SecSDLC differ from the more general SDLC?
Answer: The SecSDLC is more closely aligned with risk management practices and involves extensive
11. What is the primary objective of the SecSDLC? What are its major steps, and what are
the major objectives of each step?
Answer: The primary objective of the SecSDLC is the identification of specific threats and the risks that
12. What is a threat in the context of InfoSec? What are the 12 categories of threats presented
in this chapter?
Answer: A threat is an object, person, or other entity that represents a constant danger to an asset. The 12
13. What is the difference between a threat and an attack?
14. How can a vulnerability be converted into an attack?
15. What name is given to an attack that makes use of viruses and worms? What name is
given to an attack that does not actually cause damage other than wasted time and
resources?
16. What questions might be asked to help identify and classify information assets? Which is
the most important question to ask?
Answer:
1. Which information asset is the most critical to the success of the organization?
17. What name is given to the process of assigning a comparative risk rating to each specific
information asset? What are the uses of such a rating?
Answer: Risk assessment is the name given to the process of assigning a comparative risk rating to each
18. What term is used to describe the provision of rules intended to protect the information
assets of an organization?
19. What term is used to describe the control measure that reduces security incidents among
members of the organization by familiarizing them with relevant policies and practices in
an ongoing manner?
20. What are the three categories of InfoSec controls? How is each used to reduce risk for the
organization?
Answer: The three categories of InfoSec controls are managerial controls, operational controls, and