Certified Information Systems Security Professional CISSP · Free Practice Question Easy
Question 43
Which of the following is the LEAST effective way to evaluate and apply security governance principles?
- A Implementing security policies and procedures
- B Regularly reviewing and updating security measures
- C Conducting regular risk assessments
- D Ignoring input from stakeholders
Reveal correct answer
Correct answer: D
Explanation
The correct answer: Ignoring input from stakeholders is the least effective way to evaluate and apply security governance principles. This is because stakeholders (employees, managers, shareholders, customers, etc.) have unique perspectives and can provide valuable input based on their roles, experiences, and interactions with various aspects of the organization. They may bring to attention potential vulnerabilities, security breaches, or ineffective procedures that might have been overlooked. By ignoring their input, the organization misses the opportunity to address these issues, leading to weaker security governance. In addition, ignoring stakeholders' inputs could also lead to lower compliance and awareness of security measures, increasing the risk of security breaches. The incorrect answers: Conducting regular risk assessments is an effective way to evaluate and apply security governance principles. Regular risk assessments allow an organization to identify, evaluate, and prioritize potential vulnerabilities and threats. This allows the organization to allocate resources effectively to address these risks, improving the overall security governance. Regular risk assessments also ensure that the organization's security measures are up-to-date with the evolving threat landscape. Implementing security policies and procedures is also an effective way to evaluate and apply security governance principles. These policies and procedures establish the framework for how an organization manages its security. They provide guidelines on how to handle data, use technology, respond to security incidents, etc. Implementing these policies and procedures across the organization ensures a consistent approach to security, reduces the risk of breaches, and promotes compliance with regulations and standards. Regularly reviewing and updating security measures is a critical part of effective security governance. The cyber threat landscape is continually evolving, with new types of threats emerging regularly. By continually reviewing and updating their security measures, organizations can ensure they are equipped to handle these new threats, enhancing their overall security posture. Additionally, regular reviews can help to identify any gaps or weaknesses in the current security measures, allowing the organization to improve and strengthen these measures over time.Discussion
Think the marked answer is wrong, or have a better explanation? Share it below — comments appear after review.
You must be logged in to post a comment.
