Security Program Management and Oversight
442 soru
A enterprise healthcare technology organization is preparing for a mandatory annual compliance review by an independent external auditing firm. The compliance officer must supply an independent attestation document that proves internal data security controls over sensitive electronic protected health information (ePHI) were not only appropriately designed and implemented, but also maintained and operated effectively over a continuous 12-month evaluation window. Which of the following audit reports or attestations fulfills both the time-horizon and operational testing criteria required by the auditors?
Match each third-party risk management agreement or contractual clause to its primary operational purpose.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
A enterprise compliance team is conducting a vendor risk evaluation for a critical cloud-hosted database service. The vendor presents a security document confirming that their security control design was evaluated and validated as of a specific date last month, but it contains no testing results regarding control performance over time. The enterprise requires formal verification that controls operated effectively over a minimum six-month observation window. Which assessment deliverable should the compliance team request from the vendor?
A hospital network evaluates the financial exposure associated with a potential ransomware incident targeting its central Picture Archiving and Communication System (PACS) database server cluster. The estimated Asset Value () of the PACS cluster is . Threat intelligence and risk assessment analysts determine that a ransomware outbreak would result in an Exposure Factor () of (). Historical risk data indicates an Annualized Rate of Occurrence () of for this type of attack. What is the baseline Annualized Loss Expectancy (), in US dollars, for the PACS database cluster prior to implementing any additional security controls?
A multinational retail enterprise headquartered in Texas processes online orders for customers residing across the European Union. During an operational risk assessment, the chief information security officer observes that customer transaction logs—which include payment details, IP addresses, and email addresses—are continuously replicated to a centralized data warehouse in Dallas. The IT infrastructure team asserts that encrypting the database at rest using AES-256 satisfies all legal security duties. However, the legal compliance team insists this control is insufficient for international data flows. Which of the following best describes the organization's legal compliance obligation regarding these data transfers?
An enterprise finance company is onboarding a cloud payroll vendor and requires third-party assurance specifically regarding the vendor's internal controls over financial reporting. Which of the following reports should the enterprise request from the vendor?
During a business continuity strategy assessment, a hospital's IT security officer reviews the Business Impact Analysis (BIA) for the Electronic Health Record (EHR) system. The business impact analysis defines a Maximum Tolerable Downtime (MTD) of . Technical server restoration and database mounting are calculated to have a Recovery Time Objective (RTO) of . However, post-restoration operational steps—including data integrity validation, paper chart reconciliation, and system synchronization—require a Work Recovery Time (WRT) of . Which of the following operational conclusions should the security officer draw regarding the current disaster recovery plan?
An organization is conducting a Business Impact Analysis (BIA) and needs to define the maximum acceptable amount of time that a mission-critical system can remain offline following an outage. Which of the following business continuity metrics represents this duration?
A logistics enterprise is updating its business continuity management plan for its central warehouse execution system. A Business Impact Analysis (BIA) determines that data loss exceeding 15 minutes will cause unrecoverable state desynchronization across automated sorting units, while the system can remain completely offline for up to 6 hours before contract penalties take effect. The infrastructure team proposes a disaster recovery architecture utilizing asynchronous backup replication every 4 hours and an automated failover process that restores application availability within 2 hours. Which of the following statements correctly evaluates the proposed disaster recovery plan against the organization's business metrics?
A United States-based financial analytics organization expands its operations to process customer financial records and profile data belonging to residents of the European Union. The firm operates exclusively out of US data centers and does not hold corporate subsidiaries within the EU. Because the transfers do not fall under an overarching country-level adequacy decision for this entity, the security compliance officer must establish a valid legal transfer mechanism to remain compliant with data privacy mandates. Which of the following measures should the organization execute to lawfully authorize these international transfers of personal data?
An enterprise security team wants to evaluate the real-world behavioral impact of its security awareness training program rather than relying solely on compliance statistics. Which of the following metrics provides the best indicator that employees are actively applying security awareness principles to mitigate human risk?
An organization is evaluating risk treatment options for an aging internal document repository that contains non-sensitive archived data. Due to budget constraints, the Chief Information Security Officer (CISO) decides not to implement costly security upgrades. Instead, the organization purchases a cyber insurance policy covering potential breach liabilities for the system and signs an official memorandum documenting approval of the operational risks associated with continuing system operation without further technical modifications. Which of the following risk response strategies are being directly implemented in this scenario? (Select TWO.)
Geçerli olan tümünü seçin
A global logistics company completes a Business Impact Analysis (BIA) for its primary automated warehouse dispatch engine. The assessment reveals that to prevent irrecoverable inventory ledger corruption, data loss cannot exceed the last 15 minutes of queued transaction records preceding an outage. Furthermore, management specifies that while distribution centers can briefly operate on manual contingency protocols, the automated system must be fully restored and operational within 6 hours to prevent severe contractual SLA penalties. Which target metric configuration must the lead security architect establish to meet these operational requirements?
An airline's risk management team completes a Business Impact Analysis (BIA) for its automated crew scheduling engine. The BIA establishes that an operational disruption exceeding 8 hours will result in uncontrollable flight cancellations and severe regulatory penalties (Maximum Tolerable Downtime, MTD). After IT infrastructure restoration, technical staff require exactly 2 hours to perform database integrity checks and operational verification before handing the system back to operations (Work Recovery Time, WRT). Additionally, the business permits a maximum data loss window of 30 minutes of transaction logs. Which of the following represents the maximum Recovery Time Objective (RTO) that the IT recovery team must target to ensure compliance with the BIA?
An e-commerce organization is evaluating a third-party cloud analytics vendor that will handle non-financial telemetry and user interaction data. Prior to onboarding, the organization's compliance lead asks for a SOC 2 Type II attestation report. Which of the following statements correctly describe the scope and characteristics of a SOC 2 Type II report? (Select TWO.)
Geçerli olan tümünü seçin
A university based in the United States operates an online portal for international exchange programs, collecting personal identification details and financial records from European Union residents. Following a confirmed security incident involving unauthorized access to the application database, the compliance officer is determining legal breach notification duties. Which of the following obligations MUST the institution fulfill to satisfy regulatory compliance mandates? (Select TWO.)
Geçerli olan tümünü seçin
An information security officer at a biotechnology research institute is restructuring the organization's governance framework to align with updated compliance requirements. The officer must distinguish mandatory governance mandates from non-binding operational advice across the enterprise. Which of the following document types represent mandatory governance requirements that employees and systems must strictly follow? (Select TWO.)
Geçerli olan tümünü seçin
A regional logistics company based in the United States is expanding fleet management operations into the European Union. The engineering team plans to deploy AI-driven in-cab cameras that continuously scan driver facial features to detect signs of fatigue and alert dispatchers. Because facial scanning involves processing special category biometric data to uniquely identify individuals, the security governance team must ensure compliance with EU data privacy regulations. Which of the following actions is mandatory prior to initiating this high-risk data processing activity?
A multinational logistics firm is standardizing its wireless network infrastructure across regional distribution hubs. IT leadership issues a mandatory document detailing exact technical requirements—such as requiring WPA3-Enterprise encryption for all wireless access points—that all regional engineering teams must strictly enforce without deviation. Which of the following governance document types describes this document?
During an internal compliance audit of an online education organization, a security manager discovers that the database administration (DBA) team currently defines data sensitivity levels, determines retention schedules, and approves external data-sharing requests for student records. The DBAs also manage database backups, patch management, and access control list (ACL) configurations. Which of the following recommendations should the security manager make to properly align data governance responsibilities?