CFS136 · Principles of Information Security

Chapter 15 Review: Security Governance, Compliance, and Risk Communication

A hands-on review station for the governance hierarchy, the major regulatory frameworks, the difference between compliance and security, and how to communicate risk to different stakeholders.

Start Here

Five review stations, each a different way to practice Chapter 15. Work through them in any order. Nothing here is graded or stored, so use it as many times as you like before the quiz or the exam.

What this chapter asked you to be able to do

  • Place a statement in the governance hierarchy of policy, standard, procedure, guideline, and baseline, and explain how each level adds specificity.
  • Apply the major regulatory frameworks (GDPR, HIPAA, PCI DSS, SOX, FISMA) to a scenario and state what each one requires.
  • Explain the difference between compliance (meeting requirements) and security (actual protection), and why an organization can be compliant but insecure.
  • Communicate a technical finding as business risk by quantifying financial impact and matching the message to the stakeholder.
  • Describe third-party risk management, service level agreements, supply chain security, and responsible disclosure.

Your progress this session

These counters update as you check answers on each station. They reset when you reload the page.

0/20Terms viewed
0/8Hierarchy answers correct
0/9Framework answers correct
0/7Stakeholders matched
0/10Quiz correct
How to use each station Make a choice, then select Check to see whether it holds up and why. Every answer includes the reasoning, so a wrong pick is a chance to reread the logic rather than just the label. Keyboard users can move between tabs with the arrow keys.