Unit 1 - Questions Every CEO Should Ask About Cyber Risk Flashcards

1
Q

What is the significance of cybersecurity for CEOs?

A

Cyber threats affect businesses of all sizes and require attention from CEOs and senior leaders.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What types of critical information should CEOs consider regarding cybersecurity threats?

A

CEOs should consider the loss of:
* trade secrets
* customer data
* research
* personally identifiable information.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is a key question CEOs should ask about cybersecurity threats?

A

How could cybersecurity threats affect the different functions of my business?

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What is a recommended best practice for organizational cybersecurity?

A

Elevate cybersecurity risk management discussions to the company CEO and the leadership team.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What role does the CEO play in cybersecurity risk strategy?

A

The CEO engages in defining the organization’s risk strategy and acceptable risk levels.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

True or False: Compliance standards are sufficient for managing cybersecurity risks.

A

False

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What should organizations do to evaluate their specific cybersecurity risks?

A

Identify critical assets and associated impacts from cybersecurity threats.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What is a key metric for measuring cybersecurity effectiveness?

A

The time it takes to patch a critical vulnerability across the enterprise.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Fill in the blank: Organizations should create a _______ process to cross-train employees in risk management.

A

repeatable

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What is the importance of regular testing of incident response plans?

A

It helps prevent incidents from escalating and ensures preparedness across the organization.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What is one way to maintain workforce quality in cybersecurity?

A

Retain skilled personnel who can identify proper tools for the organization.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What should organizations maintain awareness of regarding cybersecurity?

A

Emerging cybersecurity threats.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What is the role of training for personnel in cybersecurity?

A

Training increases the likelihood of detecting and responding to cybersecurity threats.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What kind of information sharing practices can businesses adopt?

A

Foster community among different cybersecurity groups where the business is a member.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What is essential for cybersecurity program metrics?

A

Metrics should be measurable and meaningful.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What is a significant question regarding insider threats?

A

What measures do we employ to mitigate insider threats?

17
Q

What is the importance of engaging with government cyber incident responders?

A

Preparation to work with federal, state, and local government responders is crucial.

18
Q

What should CEOs regularly discuss with their boards regarding cybersecurity?

A

Risk decisions and their implications on the organization.

19
Q

What is a common misconception about cybersecurity threats?

A

The belief that ‘it can’t happen here’ is a dangerous mindset.

20
Q

What are some examples of cybersecurity threats organizations should be aware of?

A

Examples include:
* phishing emails
* malware
* ransomware.

21
Q

What resource can assist with workforce planning in cybersecurity?

A

The National Initiative for Cybersecurity Careers and Studies (NICCS).

22
Q

How can organizations ensure they are proactive in combating cybersecurity threats?

A

By establishing an organizational baseline of expected enterprise network behavior.