Apart from security requirements internal to the organisation, what other strategic goals should a Data Security Management system address?除了企业内部安全需求之外,哪些战略目标需要数据安全管理系统支撑?:()?
(A)None of these所有选项均不正确
(B)Compliance with ISO27001 and HIPPA兼容ISO27001和HIPPA
(C)Compliance with ISO29100 and PCI-DSS兼容ISO29100和PCI-DSS
(D)Regulatory requirements for privacy and confidentiality AND Privacy and Confidentiality needs of all stakeholders对于监管上要求的机密与私隐,和所有利害关系人要求的机密与私隐
(E)Ensuring the organization doesn't engage in SPAM marketing确保企业不会使用垃圾邮件做市场推广 答案解析: 该题又是典型的,题目考的是顶层设计能力,答案是微观的能力混淆大家视线。要支撑题目所说的战略目标,应该也需要一些顶层的安全设计考虑,大家看“Compliance with ISO29100 and PCI-DSS”与“Compliance with ISO27001 and HIPPA”,明显就是具体的动作,这种动作无穷无尽,因此他们俩不能选,又因为他们俩不能选,所以“None of these”肯定也不能选至于“Ensuring the organization doesn‘t engage in SPAM marketing”,也是一个相对落地的政策需求,另外,要发垃圾邮件,安全管理系统也无法进行支撑。所以,“Regulatory requirements for privacy and confidentiality AND Privacy and Confidentiality needs of all stakeholders”答案是所有答案中较好的一个,提的也是一些顶层的安全设想,虽然也不完美这题属于DAMA中那10%的困难题目。


更多CDMP数据治理试题
- 1The goal of data governance is to enable an organization to manage data as an asset.To achieve this, the DG programs must be:数据治理的目标是使组织能够将数据作为资产进行管理。为实现这一目标,DG工作必须::()?
- 2GDPR和PIPEDA是以下示例
- 3When developing a data governance scorecard在开发数据治理记分卡时:()?
- 4Who writes the data governance policy?谁编写数据治理策略?:()?
- 5Master data is data about:主数据是关于以下内容的数据::()?
- 6All the systems in the enterprise, apart from a website, are showing updated pricing information This may be due to:除网站外,企业中的所有系统都显示更新的定价信息,这可能是由于:()?