SECURITY AND PERSONNEL Flashcards
1
Q
- The general management community of interest must work with the information security professionals to integrate solid information security concepts into the personnel management practices of the organization.
A
T
2
Q
- The information security function cannot be placed within protective services.
A
F
3
Q
. In many organizations, information security teams lacks established roles and responsibilities.
A
T
4
Q
In most cases, organizations look for a technically qualified information security generalist who has a solid understanding of how an organization operates.
A
T
5
Q
- The use of standard job descriptions can increase the degree of professionalism in the information security field.
A
T
6
Q
- Builders operate and administrate the security tools and the security monitoring function and continuously improve the processes, performing all the day-to-day work.
A
F
7
Q
- Security managers are accountable for the day-to-day operation of the information security program.
A
T
8
Q
- The security manager position is much more general than that of CISO.
A
F
9
Q
- The position of security technician can be offered as an entry-level position.
A
T
10
Q
- All of the existing certifications are fully understood by hiring organizations.
A
F
11
Q
- ISSEP was developed under a joint agreement between the FBI and the United States National Security Agency, Information Assurance Directorate.
A
F
12
Q
- Each CISSP concentration exam consists of 25 to 50 questions.
A
F
13
Q
- The SSCP covers ten domains.
A
F
14
Q
- The SCNA track focuses on firewalls and intrusion detection.
A
F
15
Q
- Information security should be visible to the users.
A
F
16
Q
- The process of integrating information security perspectives into the hiring process begins with reviewing and updating all job descriptions.
A
T