考试报名
考试报名
考试内容
考试大纲
在线客服
返回顶部

备考刷题,请到

CDA认证小程序

An information security due care and due diligence activity should include which of the following?
A. Steps can be verified,measured or produce tangible artifacts on a continual basis
B. An incident response plan is created
C. Leaders are accountable and staff is aware and trained
D. Due care are steps are taken to show that company has taken responsibility
上一题
下一题
收藏
点赞
评论
题目解析
题目评论(0)

正确答案是:A: Steps can be verified,measured or produce tangible artifacts on a continual basis。

专业分析:

在信息安全领域,“尽职”和“尽责”是两个核心概念。尽职(Due Diligence)指的是持续的、系统的和可验证的安全措施,以确保信息安全的各个方面都得到充分的考虑和管理。而尽责(Due Care)指的是公司采取的措施,以展示其已经尽到责任来保护信息资产。

选项A:“Steps can be verified,measured or produce tangible artifacts on a continual basis” 直接反映了尽职的特性,即这些安全措施是可以被验证、衡量,并且能够持续产生具体的成果。这是尽职的一个关键要素,因为它强调了持续性和可验证性。

选项B:“An incident response plan is created” 虽然事件响应计划是信息安全管理的重要组成部分,但它只是一个单独的措施,不能全面代表尽职或尽责的整体活动。

选项C:“Leaders are accountable and staff is aware and trained” 强调了管理层的责任和员工的意识与培训,这属于尽责的范畴,但并不全面涵盖尽职的要求。

选项D:“Due care are steps are taken to show that company has taken responsibility” 虽然描述了尽责的概念,但并没有提到尽职的持续性和可验证性。

因此,选项A最全面地涵盖了信息安全尽职活动的核心要求。