CISSP PRACTICE QUESTIONS – 20220214

Effective CISSP Questions

According to ISO/IEC 38500, a policy stands for the overall “intentions and direction of an organization as formally expressed by its governing body or executive managers acting with appropriate authority.Which of the following best describes the concept of security management driven by policies? (Wentz QOTD)
A. Risk-based management
B. Defense in depth
C. Strategic alignment
D. Top-down approach


Kindly be reminded that the suggested answer is for your reference only. It doesn’t matter whether you have the right or wrong answer. What really matters is your reasoning process and justifications.

My suggested answer is D. Top-down approach.

Wentz’s book, The Effective CISSP: Security and Risk Management, helps CISSP and CISM aspirants build a solid conceptual security model. It is a tutorial for information security and a supplement to the official study guides for the CISSP and CISM exams and an informative reference for security professionals.

Policy Framework
Policy Framework
Security Controls
Security Controls – Layered Defense
Levels of Strategy
Levels of Strategy

Reference


根據 ISO/IEC 38500,政策代表整體“組織的意圖和方向,由其管理機構或具有適當權限的執行經理正式表達”。 以下哪項最能描述由策略驅動的安全管理的概念? (Wentz QOTD)
A. 基於風險的管理
B. 縱深防禦
C. 戰略對齊
D. 自上而下的方法

Leave a Reply