Security Governance Principles Flashcards

1
Q

At what level does Cybersecurity fall within an organization?

A

Enterprise Risk Management Decision making is done at the risk management side.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Business metrics to measure performance in relation to strategic goals and objectives. Management metrics used to inform decision making.

A

KPIs

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Approach take to achieve a goal

A

A strategy

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Mitigate risk to an acceptable level

A

Risk Management

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Achieve operational synergies and efficiencies

A

Process Integration

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Approach taken to achieve a goal

A

Strategy

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

A broad primary outcome

A

Goal

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Measurable steps taken to achieve a strategy

A

Objective

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

A tool used in support of an objective

A

Tactic

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Align departmental strategies with business strategies to support organizational goals

A

Departmental Alignment

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Optimize investments in support of business objectives.

A

Value Delivery

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Efficient and effective use of resources

A

Resource Managment

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Ensure customer and stakeholder satisfaction

A

Satisfaction

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Enhance organizational reputation with stakeholders and the broader community

A

Reputation Enhancement

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Reduce the likelihood of successful litigation by adhering to the principle of due care.

A

Reduced Liability

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Term used to describe the responsibility of leadership to determine, articulate, authorize, and fund the desired state of cybersecurity.

A

Security Governance

17
Q

The outcome when cybersecurity decision making is tied to organizational objectives

A

Strategic Alignment

18
Q

This group has a fiduciary responsibility.

A

Board of Directors

19
Q

The legal term applied to the standard of care exercised by a prudent person.

A

Due Care

20
Q

The term used to describe the investigation of a business or person prior to and during the lifetime of a relationship.

A

Due Diligence

21
Q

A logical structure

A

Framework

22
Q

What is the purpose of a framework?

A

Document and organize processes

23
Q

An operational framework contains what four things?

A

Policies Standards Guidelines Practices

24
Q

What are the 5 types of frameworks

A