Management of Information Security, Fourth Edition 7-6
Quick Quiz 1
1. The process of designing, implementing, and managing the use of collected data
elements to determine the effectiveness of a security program is known as
____________________.
2. True or False: An organization that works within an industry regulated by laws and
standards is required to meet regulatory or industry guidelines in security practices.
3. All but which of the following is one of the four factors critical to success of an InfoSec
program, as listed by SP 800-55 Rev. 1?
A. Actions-oriented measurement analysis
B. Strong upper-level management support
C. Practical InfoSec policies and procedures
D. Quantifiable performance measurements
4. Which NIST document covers basic engineering principles regarding security
baselines?
A. SP 800-27
B. SP 800-53
C. SP 800-53A
D. SP 800-11
5. What term below is used to describe security efforts that are considered among the best
in an industry?
A. Standard of due care
B. Standard of due diligence
C. Recommended business practices
D. Best security practices
Collecting InfoSec Measurements
1. Emphasize the necessity of establishing the how, when, where, and who questions of
metrics collection once an organization has determined what to measure.
2. Discuss the difference between macro-focus measurements and micro-focus