0 of 15 questions completed
Questions:
- 1
- 2
- 3
- 4
- 5
- 6
- 7
- 8
- 9
- 10
- 11
- 12
- 13
- 14
- 15
Information
TOTAL QUESTION: 15
TOTAL TIME= 15 MIN
You have already completed the Test before. Hence you can not start it again.
Test is loading...
You must sign in or sign up to start the Test.
You have to finish following quiz, to start this Test:
Your results are here!! for" IT Risk: Standards Organizations and Their Roles "
0 of 15 questions answered correctly
Your time:
Time has elapsed
Your Final Score is : 0
You have attempted : 0
Number of Correct Questions : 0 and scored 0
Number of Incorrect Questions : 0 and Negative marks 0
-
Not categorized
You have attempted: 0
Number of Correct Questions: 0 and scored 0
Number of Incorrect Questions: 0 and Negative marks 0
- 1
- 2
- 3
- 4
- 5
- 6
- 7
- 8
- 9
- 10
- 11
- 12
- 13
- 14
- 15
- Answered
- Review
-
Question 1 of 15
1. Question
Which organization develops and publishes international standards across multiple industries, including IT and security?
Correct
The International Organization for Standardization (ISO) develops and publishes international standards across multiple industries, including information technology, security, and quality management.
Incorrect
The International Organization for Standardization (ISO) develops and publishes international standards across multiple industries, including information technology, security, and quality management.
Unattempted
The International Organization for Standardization (ISO) develops and publishes international standards across multiple industries, including information technology, security, and quality management.
-
Question 2 of 15
2. Question
What is the primary focus of the Payment Card Industry Security Standards Council (PCI SSC)?
Correct
PCI SSC establishes security standards for processing, storing, and transmitting credit card information.
Incorrect
PCI SSC establishes security standards for processing, storing, and transmitting credit card information.
Unattempted
PCI SSC establishes security standards for processing, storing, and transmitting credit card information.
-
Question 3 of 15
3. Question
Which organization provides research and best practices for information security management?
Correct
The Information Security Forum (ISF) is a global, independent organization that provides research and best practices for information security management.
Incorrect
The Information Security Forum (ISF) is a global, independent organization that provides research and best practices for information security management.
Unattempted
The Information Security Forum (ISF) is a global, independent organization that provides research and best practices for information security management.
-
Question 4 of 15
4. Question
Which standards organization focuses on enterprise architecture, security, and interoperability?
Correct
The Open Group is a consortium that sets global IT standards, with a focus on enterprise architecture, security, and interoperability.
Incorrect
The Open Group is a consortium that sets global IT standards, with a focus on enterprise architecture, security, and interoperability.
Unattempted
The Open Group is a consortium that sets global IT standards, with a focus on enterprise architecture, security, and interoperability.
-
Question 5 of 15
5. Question
Which U.S. federal agency creates cybersecurity frameworks, cryptographic standards, and security-related guidelines?
Correct
The National Institute of Standards and Technology (NIST) is a U.S. federal agency that creates cybersecurity frameworks, cryptographic standards, and other security-related guidelines.
Incorrect
The National Institute of Standards and Technology (NIST) is a U.S. federal agency that creates cybersecurity frameworks, cryptographic standards, and other security-related guidelines.
Unattempted
The National Institute of Standards and Technology (NIST) is a U.S. federal agency that creates cybersecurity frameworks, cryptographic standards, and other security-related guidelines.
-
Question 6 of 15
6. Question
What does FIPS represent in the context of U.S. standards bodies?
Correct
FIPS stands for Federal Information Processing Standards and refers to standards developed by NIST for secure data processing in federal agencies and affiliated organizations.
Incorrect
FIPS stands for Federal Information Processing Standards and refers to standards developed by NIST for secure data processing in federal agencies and affiliated organizations.
Unattempted
FIPS stands for Federal Information Processing Standards and refers to standards developed by NIST for secure data processing in federal agencies and affiliated organizations.
-
Question 7 of 15
7. Question
Which organization is identified as the national standards body of the United Kingdom?
Correct
The British Standards Institution (BSI) is identified as the national standards body of the UK and develops and certifies information security and quality management standards.
Incorrect
The British Standards Institution (BSI) is identified as the national standards body of the UK and develops and certifies information security and quality management standards.
Unattempted
The British Standards Institution (BSI) is identified as the national standards body of the UK and develops and certifies information security and quality management standards.
-
Question 8 of 15
8. Question
Which ISO/IEC standard provides concepts and models for managing ICT security?
Correct
ISO/IEC 13335-1:2004 provides concepts and models for managing information and communication technology (ICT) security.
Incorrect
ISO/IEC 13335-1:2004 provides concepts and models for managing information and communication technology (ICT) security.
Unattempted
ISO/IEC 13335-1:2004 provides concepts and models for managing information and communication technology (ICT) security.
-
Question 9 of 15
9. Question
Which standard provides a framework for evaluating the security assurance of IT systems, products, and environments?
Correct
ISO/IEC TR 15443-1:2005 offers guidelines for evaluating the security assurance of IT systems, products, and environments and helps select appropriate assessment methods.
Incorrect
ISO/IEC TR 15443-1:2005 offers guidelines for evaluating the security assurance of IT systems, products, and environments and helps select appropriate assessment methods.
Unattempted
ISO/IEC TR 15443-1:2005 offers guidelines for evaluating the security assurance of IT systems, products, and environments and helps select appropriate assessment methods.
-
Question 10 of 15
10. Question
Which ISO/IEC standard defines security information objects for access control management?
Correct
ISO/IEC 15816:2002 defines security information objects (SIOs) for access control management and provides standardized terminology and structures.
Incorrect
ISO/IEC 15816:2002 defines security information objects (SIOs) for access control management and provides standardized terminology and structures.
Unattempted
ISO/IEC 15816:2002 defines security information objects (SIOs) for access control management and provides standardized terminology and structures.
-
Question 11 of 15
11. Question
Which part of ISO/IEC 15408 covers Security Functional Requirements?
Correct
ISO/IEC 15408, known as Common Criteria, is divided into three parts. Part 2 covers Security Functional Requirements.
Incorrect
ISO/IEC 15408, known as Common Criteria, is divided into three parts. Part 2 covers Security Functional Requirements.
Unattempted
ISO/IEC 15408, known as Common Criteria, is divided into three parts. Part 2 covers Security Functional Requirements.
-
Question 12 of 15
12. Question
What is the main subject of ISO/IEC 17799:2005?
Correct
ISO/IEC 17799:2005 is a Code of Practice for Information Security Management and covers areas such as risk management, business continuity, and data protection.
Incorrect
ISO/IEC 17799:2005 is a Code of Practice for Information Security Management and covers areas such as risk management, business continuity, and data protection.
Unattempted
ISO/IEC 17799:2005 is a Code of Practice for Information Security Management and covers areas such as risk management, business continuity, and data protection.
-
Question 13 of 15
13. Question
Which ISO/IEC standard defines requirements for establishing, implementing, maintaining, and continually improving an ISMS?
Correct
ISO/IEC 27001 defines requirements for an Information Security Management System (ISMS), including its establishment, implementation, maintenance, and continual improvement.
Incorrect
ISO/IEC 27001 defines requirements for an Information Security Management System (ISMS), including its establishment, implementation, maintenance, and continual improvement.
Unattempted
ISO/IEC 27001 defines requirements for an Information Security Management System (ISMS), including its establishment, implementation, maintenance, and continual improvement.
-
Question 14 of 15
14. Question
Which standard provides general principles for detecting, responding to, and recovering from security incidents?
Correct
ISO/IEC TR 18044:2004 provides general principles for handling and responding to security incidents and supports policies for detection, response, and recovery.
Incorrect
ISO/IEC TR 18044:2004 provides general principles for handling and responding to security incidents and supports policies for detection, response, and recovery.
Unattempted
ISO/IEC TR 18044:2004 provides general principles for handling and responding to security incidents and supports policies for detection, response, and recovery.
-
Question 15 of 15
15. Question
Which ISO/IEC standard serves as an assessment framework for compliance with ISO/IEC 15408 Common Criteria?
Correct
ISO/IEC 18045:2005 provides a methodology for IT security evaluation and serves as an assessment framework for compliance with ISO/IEC 15408 (Common Criteria).
Incorrect
ISO/IEC 18045:2005 provides a methodology for IT security evaluation and serves as an assessment framework for compliance with ISO/IEC 15408 (Common Criteria).
Unattempted
ISO/IEC 18045:2005 provides a methodology for IT security evaluation and serves as an assessment framework for compliance with ISO/IEC 15408 (Common Criteria).