MoIS4 CH 07 Review Questions
1. What is benchmarking?
Comparing your own process or practice or result to an external reference, such as a
2. What is the standard of due care? How does it relate to due diligence?
The standard of due care is when an organization adopts minimum levels of security for a
3. What is a recommended security practice? What is a good source for finding such
recommended practices?
Recommended security practices are security efforts that are among the best in the industry.
4. When selecting recommended practices, what criteria should you use?
When selecting recommended practices, you should use the following criteria:
5. When choosing recommended practices, what limitations should you keep in mind?
The biggest limitation to benchmarking in InfoSec is the fact that organizations do not talk to
6. What is baselining? How does it differ from benchmarking?
Baselining is a value or profile of a performance metric against which changes in the
7. What are the NIST-recommended documents that support the process of baselining?
8. What is a performance measurement in the context of InfoSec management?
Measurements are data points or computed trends that may indicate the effectiveness of
9. What types of measures are used for InfoSec management measurement programs?
Organizations use three types of measures: those that determine the effectiveness of the
10. According to Gerald Kovacich, what are the critical questions to be kept in mind when
developing a measurements program?
Why should these statistics be collected? What specific statistics will be collected? How will
11. What factors are critical to the success of an InfoSec performance program?
Four factors are critical to the success of an InfoSec performance program:
12. What is a performance target, and how is it used in establishing a measurement program?
13. List and describe the fields found in a properly and fully defined performance measurement.
As defined in Table 7-2, the elements of a properly and fully defined performance
measurement include an identifier that clearly identifies the measure, a goal or objective that
14. Describe the recommended process for the development of InfoSec measurement program
implementation.
The process for performance measurement program implementation recommended by NIST
involves six subordinate tasks:
15. Why is a simple list of measurement data usually insufficient when reporting InfoSec
measurements?
16. What is the Capability Maturity Model Integrated (CMMI), and which organization is
responsible for its development?
17. What is systems accreditation?
Systems accreditation is the authorization of an IT system to process, store, or transmit
18. What is systems certification?
Systems certification is the comprehensive evaluation of the technical and nontechnical
19. What industry standard requires system certification? How is this certification enforced?
The payment card industry requires PCI DSS certification for systems that process
20. What is the new Risk Management Framework initiative? How is it superior to the previous
approach for the certification and accreditation of federal IT systems?
The new approach is a formal methodology that brings a much more manageable and