1.0 Security and Risk Management

Governance & Compliance Practice Questions

Policies and standards, due care vs. due diligence, regulatory frameworks, IP law, and the ISC2 Code of Ethics.

One solved question, so you can see how these are marked

A multinational company wants a common structure for managing information security risk while allowing each region to satisfy local requirements. Which approach is BEST?

Adopt a recognized control framework, map applicable obligations to it, and tailor controls to business risk

A recognized framework provides a common governance and risk structure, while mapping and tailoring address legal, regulatory, and business differences. Identical controls can ignore risk and jurisdiction, PCI DSS is not a universal enterprise framework, and administrator preference lacks consistent governance.

Every question in the set below is marked like this. The answers stay hidden until you pick one.