Risk Management and Information Systems Security
[ad_1]Exam guidelines.
Section A. Essay / Short Answer (36 points)
For three possible points each, provide a very concise/brief explanation of the following in terms of Risk Management and Information Systems Security.
- When determining a long-term disaster recovery plan, there are various types of plans that may be addressed, define the following:
- Hot Site – A hot site has all the equipment available and ready to be used immediately
- Cold Site – cold site is a empty building. There is no hardware or Rackspace. You are to bring your data with you. There are no people
- Alternate Site – Alternate site is a facility to be occupied in the event that access to the primary site is prevented
- Explain why Comprehensive ST&E tests are normally grouped in general categories, such as Software, Hardware, etc.
- Explain why a Comprehensive ST&E Design Team would identify the Test Environment Required and the Test Data / Personnel Required portions of the test form.
- In 3 to 6 sentences, explain the difference between an Abbreviated ST&E and a Comprehensive ST&E.
- Briefly describe the purpose of a Risk Assessment, and generally what type of results you would expect to obtain.
- Briefly describe the purpose of an ST&E, and generally what type of results you would expect to obtain.
- Briefly define the purpose of a Contingency Plan andexplain under what condition(s) you might NOT require a complete Contingency Plan that uses an alternate, cold, or hot site for contingent situations.
- If a Risk Assessment has been completed, explain why it might be necessary for a Contingency Plan and an ST&E to be completed.
- Who should make a recommendation for the ST&E type, and who will make the determination? Why is this important?
- Why is it a good idea to let the Risk Assessment team personnel compose the ST&E Design Team, but not the ST&E Execution team?
- Briefly but thoroughly describe why a Contingency Plans should be tested regularly.
- Briefly but thoroughly describe why you will develop Contingency Plan tests for part of the Contingency Plan as opposed to always testing for Long Term loss and activation of Hot or Alternate sites.
Section B. (40 points) Multiple choice:
For two points each, select the answer that BEST completes the sentence or answers the statement in terms of Information Systems Security.
- Normally, a single person would be assigned to easily complete which of the following documents:
- Risk Assessment
- Abbreviated ST&E
- Comprehensive ST&E
- Contingency Plan
- A Network Contingency Plan should take into account:
- Long term disruption of network service, as the worst-case scenario.
- Short term disruption of network service as the most likely scenario.
- Both Long and Short-term disruption of network service
- Alternate organizational administrative procedures, automated network disaster recovery is only considered in a “COOP”.
- The purpose of the ST&E is to support at a minimum, all of the following key concepts:
- Protect, Detect, Recover
- Confidentiality, Integrity, Availability
- Destruction, Modification, Disclosure
- Assets, Threats, Safeguards (Countermeasures)
- Destruction, Disclosure, Denial of Service
- ST&Es test statements of fact that come from which Risk Assessment section:
- Asset Valutation Worksheets
- Threat Evaluation Worksheets
- ALE Calculations
- Recommended Additional Countermeasure Worksheets
- Risk Assessment Introduction
- Each in-place safeguard/countermeasure identified in a Risk Assessment should be tested by at least:
- One ST&E Test
- Two ST&E Tests
- Two ST&E Team Analysts
- Three ST&E Examiners
- Both “c” and “d”
- ST&Es generally:
- Assist the System/Network Approving Authority to make a risk management decision.
- Verify that in-place safeguards are working as intended.
- Are a series of tests to validate the security of a system or network.
- All of the above
- Only “a” and “b”.
- Only “b” and “c”.
- When conducting an Abbreviated ST&E, the Execution Team generates a complete, separate Results Report…
- After Abbreviated ST&E Execution.
- Prior to writing the Executive Summary and Introduction.
- They don’t, only the Design Team writes the Results Report.
- Never, it is not part of this type of ST&E.
- Scheduling the availability of the accounts, equipment, and interviewees for a particular test is the responsibility of:
- The Approving Authority.
- The Design Team.
- The Execution Team.
- Site Security personnel.
- According to the lecture, which of the following must Contingency Plans address?
- Emergency Response
- Backup Operations
- Activation Financial Section
- Recovery Actions
- Hot Site Activation Procedures
- I, II, and III.
- I, II, and IV
- II, III, and IV
- I, III, and V
- III, IV, and V
- The most cost-effective method for long term resumption of organizational operations after a disaster is:
- Hot Site
- Warm Site
- Cold Site
- Alternate Site
- The least cost-effective method for long term resumption of organizational operations after a disaster is:
- Hot Site
- Warm Site
- Cold Site
- Alternate Site
- Rotations of backup tapes do not require use and expenditures of off-site backups because you can go so far back in recovery-history.
- True
- False
- When developing a “short-term loss” response portion of a contingency plan and considering options for a mission-critical system or network, which of the following are NOT important to consider:
- Hot Site Activation
- User Denial of Service
- Revenue Loss
- Relocation of Personnel
- According to the lecture, some organizations consider Disaster Recovery Plans and _____ to be organizational-wide, rather than system-specific.
- Contingency Plans (CPs)
- Continuity-of-Operation Plans (COOPs)
- Disaster Recovery Emergency Response Plans (DRERPs).
- Personnel Relocation Plans (PRPs).
- There are occasions when you do NOT need a contingency plan.
- True
- False
- The Primary Purpose(s) for testing a Contingency Plan is:
- Determining the effectiveness of the CP.
- Finding the inadequacies of the CP.
- Updating the CP and Training the personnel as to their duties.
- Ensuring that management has invested properly in the alternate/hot/cold site.
- According to the reading, a contingency plan should consist of all of the following EXCEPT:
- Action plan
- Preliminary Plan
- Risk Assessment
- Preparatory Actions
- Threat identification is an important part of both risk assessments and contingency plans.
- True
- False
- According to the lecture, CPs must contend with Testing/Training and which of the following issues?
- Short Term and Long Term Loss.
- Hot Site Activation Procedures
- Activation Financial Issues
- CP Design Team Composition.
- The ST&E Execution Team writes new Tests when:
- The Design Team could not complete the tests before the Execution Team began their portion of the process.
- The Execution Team discovers new vulnerabilities.
- The Execution Team disagrees with the way the design team wrote the test.
- None of the above, the execution team does not normally write tests.
Section C. (24 points) Practical Application Essay Question
You are tasked with designing a security, test and evaluation (ST&E) for two of the risks cited in your own risk assessment exercise, that you will hand in as the written requirement for the course. Please note that you are on the design team preparing the ST&E documents before the team arrives on location, for use by the auditors who will conduct the actual ST&E.
Hints. This essay question tests how thoroughly Students design the ST&E audit, before anyone goes out and conducts the audit. If the ST&E audit is designed correctly, the ST&E auditor who actually conducts the audit will have a guideline that causes him/her to look at the right places and ask the right persons the right questions, to discover if the safeguards are indeed in place and working. Since the ST&E audit has not been done yet,
[Button id=”1″]
[ad_2]
Source link
"96% of our customers have reported a 90% and above score. You might want to place an order with us."
