Answer the questions with at least 1 reference per question. The length of each question should be a minimum of 6-8 sentences. 1. Discuss how your organization, within the topic assignment (Augusta Medical Hospital), will use data governance and IT governance. Explain why and how they are different. 2. Explain the CIO and the CISO’s roles and responsibilities accountable for information governance within your security organization and how each position is supported. 3. Does the government or any organization have the right to impose a cybersecurity framework on personal or private assets? Explain your rationale. 4. Is the IoT governable by frameworks? Explain your rationale. 5. From a business perspective, explain why continuous improvement is absolutely necessary for an information assurance/information governance program. 6. Outline one recent incident where failure to adhere to information governance (in favor of budget) resulted in significant financial loss. Explain how the article you selected relates to informational governance. 7. When testing and validation is performed using internal resources and personnel, explain why the findings and results cannot be simply presented to IT managers. 8. Explain why testing technical controls, defensive software, and sensitive assets must, whenever possible, be performed on alternate (e.g., backup) systems or high-fidelity virtual environments. 9. Discuss the systems/methods/software/services required to detect a breach or an intrusion. Discuss elements necessary within the security architecture to isolate corporate assets should an intrusion occur (e.g., ransomware). 10. Discuss the difference and complexities involved in detecting and responding to internal data breaches as opposed to external data breaches and incidents. 11. How can a security professional cultivate a culture of security awareness, collaboration, and buy-in among management, staff, clients, and stakeholders? Present an example with rationale. 12. An organization should request a background check before employment for all employees and monitor certain employees’ activities. Do you agree or disagree? Justify your response. 13. What is the significance of configuration and Patch management, and how can we deploy it to reduce or eliminate the potential of exploitation? 14. In light of common budget constraints, explain at least two creative ways to incorporate nontechnical controls for technical problems. 15. Assess the effectiveness of the security program and explain how you will apply your knowledge to effectively manage a security program. 16. What things should you avoid when creating an emergency operations plan? Explain.