1. Which of the following terms is described as the process of designing, implementing, and managing the use of the collected data elements to determine the effectiveness of the overall security program?
- Baselining
- Performance management
- Best practices
- Standards of due care/diligence
- Those that determine the effectiveness of the execution of InfoSec policy
- Those that evaluate the compliance of non-security personnel in adhering to InfoSec policy
- Those that assess the impact of an incident or other security event on the organization or its mission
- Those that determine the effectiveness and/or efficiency of the delivery of InfoSec services
3. Which of the following has the main goal of restoring normal modes of operation with minimal cost and disruption to normal business activities after an adverse event?
- Business response
- Risk management
- Contingency planning
- Disaster readiness
- Incident response
- Business continuity
- Project management
- Disaster recovery
- Restore data from backups
- Create the incident damage assessment
- Restore services and processes in use
- Conduct an after-action review
No comments:
Post a Comment