최신ISC Certified in Governance Risk and Compliance - CGRC무료샘플문제
What is the four-step security categorization process?
Response:
Which of the following system security policies is used to address specific issues of concern to the organization?
Response:
An organization monitors the hard disks of its employees' computers from time to time. Which policy does this pertain to?
Response:
During which Risk Management Framework (RMF) step is the system security plan initially approved? Response:
The official management decision given by a senior organizational official to authorize operation of an information system and to explicitly accept the risk to organizational operations (including mission, functions, image, or reputation), organizational assets, individuals, other organizations, and the Nation based on the implementation of an agreed-upon set of security controls.
Response:
Which of the following individuals is responsible for the final accreditation decision? Response:
Which RMF role establishes risk management roles and responsibilities and provides advice and relevant information to authorizing officials concerning the risk management strategy to guide authorization decision making.
Response:
NIST SP 800-37, Revision 1, was developed by NIST under the authority of Response:
An Authorizing Official plays the role of an approver. What are the responsibilities of an Authorizing Official?
Each correct answer represents a complete solution. Choose all that apply.
Response:
When should the assessment team provide the briefing following the conclusion of testing to provide system management/operations personnel an opportunity to know the security posture and take immediate actions; 24 hrs, 48 hrs, immediately)?
Response:
Ensuring timely and reliable access to and use of information. SP 800-53; SP 800-53A; CNSSI-
4009; SP 800-27; SP 800-60; SP 800-37; FIPS 200; FIPS 199; 44 U.S.C., Sec.
Response:
An organizational official with statutory or operational authority for specified information and responsibility for establishing the controls for its generation, collection, processing, dissemination, and disposal is known as the:
Response:
The Security Category that guards against the improper modification or destruction of information and includes ensuring information non-repudiation & authenticity.
Response:
Who initiates system authorization process and has the full responsibility over the life cycle of an information system?
Response: