Certified Information Systems Security Professional – CISSP – Question016

A security professional determines that a number of outsourcing contracts inherited from a previous merger do not adhere to the current security requirements. Which of the following BEST minimizes the risk of this happening again?

A.
Define additional security controls directly after the merger
B. Include a procurement officer in the merger team
C. Verify all contracts before a merger occurs
D. Assign a compliancy officer to review the merger conditions

Correct Answer: D

Certified Information Systems Security Professional – CISSP – Question013

Which of the following entails identification of data and links to business processes, applications, and data stores as well as assignment of ownership responsibilities?

A.
Security governance
B. Risk management
C. Security portfolio management
D. Risk assessment

Correct Answer: B

Certified Information Systems Security Professional – CISSP – Question009

Intellectual property rights are PRIMARY concerned with which of the following?

A.
Owner’s ability to realize financial gain
B. Owner’s ability to maintain copyright
C. Right of the owner to enjoy their creation
D. Right of the owner to control delivery method

Correct Answer: D

Certified Information Systems Security Professional – CISSP – Question008

An important principle of defense in depth is that achieving information security requires a balanced focus on which PRIMARY elements?

A.
Development, testing, and deployment
B. Prevention, detection, and remediation
C. People, technology, and operations
D. Certification, accreditation, and monitoring

Correct Answer: C

Explanation: