Thursday 10 January 2019

CISSP Question Answer

Which of the following choices is NOT part of a security policy?

A. definition of overall steps of information security and the importance of security
B. statement of management intend, supporting the goals and principles of information security
C. definition of general and specific responsibilities for information security management
D. description of specific technologies used in the field of information security

Answer: D

In an organization, an Information Technology security function should:


A. Be a function within the information systems functions of an organization
B. Report directly to a specialized business unit such as legal, corporate security or insurance
C. Be lead by a Chief Security Officer and report directly to the CEO
D. Be independent but report to the Information Systems function

Answer: C

No comments:

Post a Comment

Note: only a member of this blog may post a comment.