CGRC Exam Question 1
The transfer of risk is one of the five risk treatment methods pointed out in NIST 800-37 Rev 2.
Choose an example of risk transfer from the following options.
Response:
Choose an example of risk transfer from the following options.
Response:
CGRC Exam Question 2
An application that requires special attention to security due to the risk and magnitude of harm resulting from the loss, misuse, or unauthorized access to or modification of the information in the application. Note: All federal applications require some level of protection. Certain applications, because of the information in them, however, require special management oversight and should be treated as major.
Adequate security for other applications should be provided by security of the systems in which they operate.
Response:
Adequate security for other applications should be provided by security of the systems in which they operate.
Response:
CGRC Exam Question 3
A security policy is an overall general statement produced by senior management that dictates what role security plays within the organization. Which of the following are required to be addressed in a well designed policy?
Each correct answer represents a part of the solution. Choose all that apply.
Response:
Each correct answer represents a part of the solution. Choose all that apply.
Response:
CGRC Exam Question 4
The emphasis of the revised NIST SP 800-37 process is on.............
Response:
Response:
CGRC Exam Question 5
Management policy and procedures designed to maintain or restore business operations, including computer operations, possibly at an alternate location, in the event of emergencies, system failures, or disaster.
Response:
Response:
