MoIS4 CH05 Review Questions
1. What is an InfoSec program?
An InfoSec program is the structure and organization of the effort to contain risks an
2. What functions constitute a complete InfoSec program?
A complete InfoSec program consists of risk assessment, risk management, systems testing,
3. What organizational variables can influence the size and composition of an InfoSec
program’s staff?
4. What is the typical size of the security staff in a small organization? A medium-sized
organization? A large organization? A very large organization?
Small: one full-time/part-time manager and up to two part-time support staff members
5. Where should an InfoSec unit be placed within an organization? Where shouldn’t it be
placed?
In large organizations, it is placed within the IT department. But if the roles of the CIO and CISO
6. Into what four areas should the InfoSec functions be divided?
Functions performed by nontechnical areas of the organization, functions performed by IT staff
7. What are the roles that an InfoSec professional can assume?
The most frequently encountered positions are chief information security officer (CISO), security
8. What are the three areas of a SETA program?
The three areas of SETA are education: building in-depth knowledge as needed to design,
9. What can influence the effectiveness of a training program?
Factors that influence effectiveness include:
10. What are some of the various ways to implement an awareness program?
11. Which two NIST documents largely determine the shape of an InfoSec program? Which
other documents can assist in this effort?
“SP 800-14: Generally Accepted Principles and Practices for Securing Information
12. What are the elements of a security program, according to NIST SP 800-14?
According to “SP 80014,” the elements of a security program are: policy, program management,
13. InfoSec positions can be classified into what three areas? Describe each briefly.
The three categories of InfoSec positions are: those that define (i.e., provide policies, guidelines,
14. Describe the two overriding benefits of education, training, and awareness.
The benefits of awareness, training, and education include improving employee behavior as
15. What is the purpose of a SETA program?
The purpose of a SETA program is to enhance security by providing education, training, and
16. Which of the SETA program’s three elements—education, training, and awarenessis
the organization best prepared to provide itself? Which should it consider outsourcing?
Security awareness is the element organizations are best prepared to provide themselves.
17. How does training differ from education? Which of the two is offered to a larger
audience with regard to InfoSec?
Education mostly describes “why” there’s a need for security within an organization. It helps the
18. What are the various delivery methods for training programs?
Delivery methods for training include:
One-on-oneA dedicated trainer works with each trainee on the areas specified.
19. List the steps in a seven-step methodology for implementing training.
The recommended steps are:
Identify program scope, goals, and objectives.
20. When developing an awareness program, what priorities should you keep in mind?
Priorities for awareness programs include:
Focus on people both as part of the problem and as part of the solution.