Which of the following is NOT a state in which informatio n exists?


_______ A)


B) Stored


D) Factor ed 2 )

Why is it important to consistent ly enforce policy, and not "go easy on someone" ?


_______ A)

es should never be broken

Playing favorites D)

creates resentment

It is easier to 3)

defend in court

Which of the following is LEAST likely to lead to employee s accepting and following policy?


_______ A)

t from the organiz ation when develo ping policies

Consistently D)

enforce policies

Make policy 4)

compliance part of the job descriptions

Why is it important to prepare written policies?


_______ A)

olicies can be commu nicated more easily

This helps to D)

ensure consistency

It is required by 5)


Why is it important for leadership to set a tone of complianc e with policy?


_______ A)

e the ones that write the policies

The rest of the D)

organization feels better about following the rules

It is part of their 6)


When should informatio n security policies, procedure s, standards , and guidelines be revisited?


_______ A)

As indicated in the policy D)

When dictated by 7)

change drivers

Which is the best way to foster acceptanc e of a new policy?


_______ A)

detaile d enough that everyo ne will underst and it

Involve people in D)

policy development by conducting interviews

Give everyone a 8)

copy of the policy after it is written

Which is a two wall challenge ?


_______ A)

Screened-subnet D)


Requiring security badges at both doors to a room


Which is the preferred approach to organizing informatio n security policies, procedure s, standards , and guidelines ?


_______ A)

Combine policies D)

and procedures

Keep them all



Why do we need the GrahamLeachBliley Act (GLBA)?


______ A)

Businesses need D)

expert advice to achieve and sustain compliance

It protects banks

from lawsuits due to a lack of fair treatment of employees


What should be the conseque nces of informatio n security policy violations ?


______ A)

Always up to, and D)

including, termination

Violations should

be cited in the person's annual performance review


Leadershi p by setting the example, or "do as I do", is considere d:


______ A)

The same as D)

"management by walking around"

Ineffective in a

high-tech company


Why is it important to remind people about best practice informatio n security behaviors ?


______ A)

This approach is a mandatory requirement of information security policies D)

Reminders are the least expensive way to ensure compliance with policies


Which is the worst that may happen if informatio n security policies are out of date, or address technologi es no longer used in the organizati on?


______ A)

People may not D)

know which policy applies

People may take

the policies less seriously, or dismiss them entirely


Which is the best goal for a new policy?


______ A)

Secure and protect assets from foreseeable harm, and provide flexibility for the unforeseen D)

Comply with

applicable government policy


Which part of the U.S. Constituti on is analogous to the first approved version of a new informatio n security policy?


______ A)


B) The



D) The

Bill of


In what way are the Torah and the U.S. Constituti on like informatio n security policies?


______ A)

rules to guide behavi or in suppor t of organi zation al goals

They include D)

business rules

They contain

articles and amendments


What issue is addressed by both the Bible and corporate policies?


______ A)

The behavior of D)

people in power

People tend to

forget things if they are not periodically reminded of their obligations

SHORT ANSWER. Write the word or phrase that best completes each statement or answers the question. 19)

An informatio n security ________ exists when users share account names and password s with each other.


______ _______


An organizati on which does not enforce policy is said to have ________ policies.


______ _______


The ________ are either elected or chosen to direct the affairs of a corporatio n, and are responsibl e for providing oversight of the informatio n security program.


______ _______


According to HIPAA, private health care informatio n must remain protected from damage, misuse, and ________.


______ _______


The U.S. Constituti on's ________ are the built-in framewor k that makes it possible to change the document , while still adhering to its original intent.


______ _______


Match information security function each role with its responsibi lities to the right: I. Board of Directors A. Ensure that informatio n security controls are functionin g intended II. Informatio n Owner B. Approve written informatio n security policies III. Data Custodian C. Establish the controls that provide informatio n security IV. ISOD. Process and store informatio n V. Internal Auditor E. Administe r the


______ _______ 25 )

Match the deal with another following terms to their meanings: I. Foreign Policy A. Policy adopted by society through legislative means to govern its people II. Law B. Civil or criminal; imposed for violations III. Policy Area C. A general topic, which relates to specific behavior and expectati ons IV. Penalty D. Standards for public and private education V. Education Policy E. Ways and means for one nation to


______ _______

1 )

D 2)

A D 3 )4 )

C 5)

C 6)

D 7)

C 8)

B 9)

A 10)

B 11)

B 12)

B 13)

B 14)

D 15)

C 16)

A 17)

B 18)

A 19)

gap 20)

paper only 21)

Board of Directors 22)

disclo sure 23)

amen dments 24)

BCD EA 25)