0% found this document useful (0 votes)
15 views4 pages

CIA Triad and Risk Management Explained

Uploaded by

rifatcse10
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
15 views4 pages

CIA Triad and Risk Management Explained

Uploaded by

rifatcse10
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd

1. What does the "availability" component of the CIA triad primarily ensure?

a) That data is only accessible to authorized users.


b) That data is accurate, consistent, and unaltered.
c) That systems and data are accessible to authorized users when needed.
d) That users are held accountable for their actions.
2. Which of the following is the best example of a threat to confidentiality?
a) A database server going offline due to a power failure.
b) An attacker intercepting unencrypted network traffic to steal credentials.
c) A user accidentally deleting a critical company spreadsheet.
d) A hacker injecting malicious code into a website's input field.
3. The principle of non-repudiation primarily addresses which aspect of a security
transaction?
a) It proves that a user's identity is valid.
b) It ensures that a sender cannot later deny sending a message.
c) It guarantees that data has not been altered in transit.
d) It provides a complete audit trail of user activities.
Risk management
4. In risk management, what is a "vulnerability"?
a) A person or group that poses a potential danger to an asset.
b) An intentional or accidental act that could cause harm.
c) A weakness or gap in a system's protection efforts.
d) The potential harm that could occur if a threat exploits a vulnerability.
5. Which risk treatment strategy involves moving the financial impact of a risk to
a third party, such as an insurance company?
a) Risk avoidance
b) Risk mitigation
c) Risk transfer
d) Risk acceptance
6. Senior management has decided that the cost of implementing a new security
control outweighs the potential financial loss of a low-probability risk. What risk
treatment strategy is being applied?
a) Risk avoidance
b) Risk mitigation
c) Risk transfer
d) Risk acceptance
Security controls and governance
7. Which type of security control is a company firewall considered?
a) Administrative
b) Technical
c) Physical
d) Corrective
8. An organization's written policy that outlines employees' responsibilities for
acceptable network use is an example of what type of control?
a) Administrative
b) Technical
c) Physical
d) Compensating
9. When a security guard is posted at the entrance of a data center, what type of
control is being used?
a) Administrative
b) Technical
c) Physical
d) Detective
10. What is the purpose of a compensating control?
a) To deter an attacker from performing a malicious act.
b) To correct an incident that has already occurred.
c) To provide an alternative to a primary control that is difficult or impossible to
implement.
d) To detect an ongoing attack.
Ethics and professional practice
11. According to the ISC2 Code of Ethics, what is the primary duty of an
information security professional?
a) To protect society, the commonwealth, and the infrastructure.
b) To act honorably, honestly, justly, and responsibly.
c) To provide competent service to their principals.
d) To always protect confidential information.
12. An employee is offered a large sum of money by a competitor for access to
their company's proprietary information. The employee declines the offer and
immediately reports the incident to management. What ethical canon has the
employee demonstrated?
a) Upholding the rights of all individuals.
b) Protecting society, the commonwealth, and the infrastructure.
c) Providing diligent and competent service to their principals.
d) Acting honorably, honestly, justly, and responsibly.
Answers and explanations

1. c) That systems and data are accessible to authorized users when needed.
Availability ensures that information systems and data are ready for use by
authorized parties when required.
2. b) An attacker intercepting unencrypted network traffic to steal credentials.
Intercepting unencrypted traffic is a direct threat to confidentiality because
sensitive information is exposed to an unauthorized party.
3. b) It ensures that a sender cannot later deny sending a message. Non-
repudiation provides a strong form of accountability, preventing a party from
successfully disputing the origin or authenticity of a communication.
4. c) A weakness or gap in a system's protection efforts. A vulnerability is a flaw
or weakness, not the threat actor or the potential harm itself.
5. c) Risk transfer. This is the definition of risk transfer, where the financial
responsibility for a loss is shifted to another entity.
6. d) Risk acceptance. This is a deliberate decision by management to take no
action on a risk, typically because the cost of countermeasures is not justified.
7. b) Technical. Firewalls are hardware or software controls used to protect against
cyber threats, making them a technical control.
8. a) Administrative. Policies, procedures, and standards are all examples of
administrative controls that define security rules and expectations.
9. c) Physical. Security guards, fences, and locks are all tangible controls designed
to protect physical assets.
10. c) To provide an alternative to a primary control that is difficult or
impossible to implement. A compensating control is used when a specific
security control cannot be implemented due to technical or business constraints.
11. a) To protect society, the commonwealth, and the infrastructure. While all
the options are related to the Code of Ethics, this is the first and most
fundamental canon.
12. c) Providing diligent and competent service to their principals. By refusing
the bribe and reporting the incident, the employee acted in the best interest of
their employer (the principal), which is a key ethical canon.

Common questions

Powered by AI

Technical security controls, such as firewalls, are designed to be protective measures implemented through technology to safeguard against cyber threats. On the other hand, physical security controls, such as security guards, secure the physical premises and infrastructure. Implementing both types of controls is vital as it covers comprehensive security needs, protecting information systems from digital threats and physical unauthorized access .

Vulnerabilities are weaknesses or gaps in a system's protection efforts, while threats are potential dangers that can exploit these vulnerabilities to cause harm. The interplay between the two is critical as effective risk management involves identifying and mitigating vulnerabilities to reduce the likelihood or impact of threats. Understanding this relationship enables organizations to prioritize security measures and allocate resources efficiently to prevent potential breaches .

Risk transfer involves moving the financial impact of a risk to a third party, such as through insurance. This strategy is advantageous as it reduces the financial burden of potential risks by allowing an organization to manage its financial planning more effectively and predictably, enabling it to focus resources on core business functions without the looming uncertainty of bearing all potential loss costs .

Defining acceptable network use policies as administrative controls is critical for organizations as it sets clear expectations and boundaries for employee behavior regarding network and data use. This helps to prevent misuse and enables consistent enforcement of security standards, protecting against insider threats and data breaches by ensuring that all users understand the security implications of their actions .

The CIA triad's focus on availability ensures that information systems and data are accessible to authorized users when needed, which is essential for maintaining operational reliability. This aspect is crucial for business continuity, as downtime can result in significant operational disruptions and financial losses. Ensuring availability involves implementing redundant systems, robust infrastructure, and effective incident management procedures to minimize service interruptions .

According to the ISC2 Code of Ethics, the primary duty of an information security professional is to protect society, the commonwealth, and the infrastructure. This foundational canon obligates professionals to prioritize the public good and ensure the infrastructure's resilience against threats .

Compensating controls provide an alternative security measure that achieves the same objective as the primary control, which may be difficult or impossible to implement due to constraints. These controls ensure that security is maintained by adapting to the existing limitations while still addressing the identified risk effectively .

Ethics in information security significantly influence an employee’s decision-making process by providing a moral compass that prioritizes acting honorably, justly, and responsibly. For example, when faced with a conflict-of-interest situation such as a bribery offer from a competitor, adherence to ethical principles compels the employee to decline the offer and report the incident, thus upholding professional integrity and protecting the employer's interests .

Senior management might choose risk acceptance when the potential financial impact of a risk is low and the cost of implementing mitigation strategies outweighs the benefits. By accepting the risk, management decides to endure potential losses because it is economically justifiable or resource constraints limit the company's ability to address it .

Non-repudiation ensures that a sender cannot later deny having sent a message, thus providing a strong form of accountability. This prevents parties from successfully disputing the origin or authenticity of a communication, which is crucial in verifying and validating digital transactions .

You might also like