01. Enterprise Governance Flashcards
Enterprise Governance
“A process whereby senior management exerrts strategic control over business functions through policies, objectives, delegation of authority, and monitoring”
This is a definition of what fucntion
GOVERNANCE
33
Enterprise Governance
GOVERNANCE is a process whereby senior management exerts strategic control over business functions through what 4 methods
- POLICIES
- OBJECTIVES
- DELEGATION OF AUTHORITY
- MONITORING
33
Enterprise Governance
GOVERNANCE provides the management oversight of the business to ensure business processes effectively meet the organisations business ____ and ____
- VISION
- OBJECTIVES
33
Enterprise Governance
- Organisations usually establish governance through the use of what body of people
- This body of people is usually responsible for seeting what business strategy
- STEERING COMMITTEE
- LONG TERM
- Organisations usually establish governance through steering committees responsible for setting long term business strategy and making changes ot ensure that busines sprocesses continue to support business stragegy and the oragnisations overall needs
33
Enterprise Governance
“Organisations usually establish governance through steering committees responsible for setting long term business strategy and making changes ot ensure that busines sprocesses continue to support business stragegy and the oragnisations overall needs”
This is accomplished through the development and enforcement of what 4 things
- POLICIES
- STANDARDS
- PROCEDURES
- REQUIREMENTS
33
Enterprise Governance
Information security governance typically focuses on several key processes which include;
[ ] Personnel Management
[ ] Vendor hardware selection
[ ] Sourcing
[ ] Risk Management
[ ] Certicication and Training
[ ] Configuration Management
[ ] Change Management
[ ] Operating system selection
[ ] Access Management
[ ] Vulnerability Management
[ ] Team resource size
[ ] Incident Management
[ ] BCP
[X] Personnel Management
[ ] Vendor hardware selection
[X] Sourcing
[X] Risk Management
[ ] Certicication and Training
[X] Configuration Management
[X] Change Management
[ ] Operating system selection
[X] Access Management
[X] Vulnerability Management
[ ] Team resource size
[X] Incident Management
[X] BCP
33
Enterprise Governance
Information Security is a BUSINESS or STRATEGIC issue
BUSINESS
34
Enterprise Governance
The main reason typically cited for an information security business issue is what, in relation to individuals in particular roles
LACK OF UNDERSTANDING AND COMMITMENT
(board of directors and snr. exec)
34
Enterprise Governance
- Many people in a business see information security as what sort of issue
- In order to be successful, information security must be considered what sort of issue
- TECHNOLOGY ISSUE
- PEOPLE ISSUE
34
Enterprise Governance
How can a business be in a position of reduced risk in relation to people at all levels
UNDERSTAND ROLES AND RESPONSIBILITIES
- When people at each level in the organisation understand the importance and impact of information security, their own roles and responsibilities, the organisation will be in a position of reduced risk
34
Enterprise Governance
Information security governance is a set of established activities that helps management understand what 3 things in relation to the organisation
- STATE OF SECURITY PROGRAM
- CURRENT RISKS
- DIRECT ACTIVITIES
34
Enterprise Governance
A goal of the security program is to contribute towards what in relation to the wider business
SECURITY STRATEGY
34
Enterprise Governance
in order for a security governance program to succeed, what else should the business have established and in place
IT GOVERNANCE PROGRAM
34
Enterprise Governance
“The desired capabilities or end states are ideally expressed in achievable, measurable terms”
This is the defnition of what artifact or action that forms part of a healthy security governance program
OBJECTIVES
35
Enterprise Governance
“This is a plan to achieve one or more objectivies”
This is the defnition of what artifact or action that forms part of a healthy security governance program
STRATEGY
35
Enterprise Governance
“At a minimum, ____ should directly reflect the mission, objectives, and goals of the overall organisation”
This is the defnition of what artifact or action that forms part of a healthy security governance program
POLICY
35
Enterprise Governance
“These should flow directly from the organisations mission, objectives and goals. Whatever is most important to the organisation should also be essential to information security”
This is the defnition of what artifact or action that forms part of a healthy security governance program
PRIORITIES
35
Enterprise Governance
“The technologies, protocols, and practices used by IT should align with the organisations needs. On their own, ____ help drive a consistent approac to solving business challenges. A choice of these should facilitate solutions that meet the organisations needs in a cost-effective and secure manner”
This is the defnition of what artifact or action that forms part of a healthy security governance program
STANDARDS
- The choice of standards should facilitate solutions that meet the organisations needs in a cost effective and secure manner
35
Enterprise Governance
“Formalised descriptions of repeated business activities include instructions to applicable personnel. Include one or more procedures and definitions of business records and other facts that help workers understand how things are supposed to be done”
This is the defnition of what artifact or action that forms part of a healthy security governance program
PROCESSES
35
Enterprise Governance
“The are formal descriptions of critical activities to ensure desired outcomes”
This is the defnition of what artifact or action that forms part of a healthy security governance program
CONTROLS
35
Enterprise Governance
“The organisations IT and security programs and projects should be organised and performed in a consistent manner that reflects business priorities and supports the business”
This is the defnition of what artifact or action that forms part of a healthy security governance program
PROGRAM & PROJECT MANAGEMENT
35
Enterprise Governance
“____ includes the formal measurement of processes and controls so that management understands and can measure them”
This is the defnition of what artifact or action that forms part of a healthy security governance program
METRICS/REPORTING
35
Enterprise Governance
Security governance should be practiced in a business in the same way it performs governance in what 2 other areas
- IT GOVERNANCE
- CORPORATE GOVERNANCE
35
Enterprise Governance
“Management will ensure that risk assessments are performed to identify risks in information systems and supported processes. Follow up actions will bec arried out to reduce the risk of system failure and compromise”
This is a definition of which activity required to protect the organisation
RISK MANAGEMENT
36
Enterprise Governance
“Management will ensure that key changes will be made to business processes that will resul tin security improvement”
This is a definition of which activity required to protect the organisation
PROCESS IMPROVEMENT
36
Enterprise Governance
“Management will put technologies and processes in place to ensure that security events and incidents will be identified as quickly as possible”
This is a definition of which activity required to protect the organisation
EVENT IDENTIFICATION
36
Enterprise Governance
“Management will put incident response procedures into place to help avoid incidents, reduce impact and probability of incidents, and improve response to incidents to minimise their impact on the organisations”
This is a definition of which activity required to protect the organisation
INCIDENT RESPONSE
37
Enterprise Governance
“Management will identify all applicable laws, regulations, and standards and carry out activitiys to confirm that the orgnaisation can attain and maintain compliance”
This is a definition of which activity required to protect the organisation
IMPROVED COMPLIANCE
37
Enterprise Governance
“Management will define objectives and allocate resources to develop business continuity and disaster recovery plans”
This is a definition of which activity required to protect the organisation
BCP/DR PLANNING
37
Enterprise Governance
“Management will establish processes to measure key security events such as incidents, policy changes and violations, audits, and training”
This is a definition of which activity required to protect the organisation
METRICS
37
Enterprise Governance
“The allocation of workforce budget, and other resources to meet security objectives is monitored by management”
This is a definition of which activity required to protect the organisation
RESOURCE MANAGEMENT
37
Enterprise Governance
“An effective security governance program will result in better strategic descisions in the IT organisation that keep risks at an acceptably low level”
This is a definition of which activity required to protect the organisation
IMPROVED IT GOVERNANCE
37
Enterprise Governance
What are the 2 key results of having an effective security governance program in place
- INCREASED TRUST
- IMPROVED REPUTATION
- Customers, suppliers, and partners will trust the organisations to a greater degree when they see that security is managed effectively
- The business community, including custoemrs, investors, and regulators, will hold the organisation in higher regard
37
Enterprise Governance
To be business aligned, people in the security pgoram should be aware of what 5 charactersitics of the organisations;
[ ] Size and No. of Employees
[ ] Culture
[ ] Asset Value
[ ] Number of assets
[ ] Back up Objective
[ ] Risk Tolerance
[ ] Legal Obligations
[ ] Most importance client
[ ] Market Conditions
[ ] Size and No. of Employees
[X] Culture
[X] Asset Value
[ ] Number of assets
[ ] Back up Objective
[X] Risk Tolerance
[X] Legal Obligations
[ ] Most importance client
[X] Market Conditions
38
Enterprise Governance
A risk associated with an overzelous security manager who is more risk-averse than the business itself causing groups within the business to bypass corporate IT processes and procure their own solutions
SHADOW IT
38
Enterprise Governance
Goals and objectives further the organisations mission, helping it to achieve what;
[ ] Attract new customers
[ ] Have a large workforce
[ ] Increase market share
[ ] Increase revenue/profitability
[ ] Grow rapidly
[X] Attract new customers
[ ] Have a large workforce
[X] Increase market share
[X] Increase revenue/profitability
[ ] Grow rapidly
38
Enterprise Governance
What is the ISACA definition of risk appetite
“Level of risk an organisation is willing to accept while purusing its mission, strategy, and objectives before taking action to treat the risk”
39
Enterprise Governance
“the term used that describes how people within an organisation treat one another and how they get things done”
This is a definition of what
ORGANISATIONAL CULTURE
39
Enterprise Governance
The way that an organisations leaders treat each other sets what to the rest of the employees
BEHAVIORAL NORMS
39
Enterprise Governance
A culture that affects how the organisation deals with risk and how it treats risk over time
RISK CULTURE
39
Enterprise Governance
A formal policy statement that defines permitted activities and forbidden activities in an organisation
ACCEPTABLE USE POLICY
(AUP)
39
Enterprise Governance
A policy that sets to regulate the behaviour of professional sand ensure that those professionals maintain a high standard of conduct
CODE OF ETHICS
aka code of conduct
40
Enterprise Governance
The UK act and year that sets out the prohibition of individuals or organisations bribing foreign government officals
UK BRIBERY ACT 2010
40
Enterprise Governance
Laws, Regulations, Professional standards and requirements are all examples of INTERNAL or EXTERNAL governance
EXTERNAL
40
Enterprise Governance
As well as laws, regulations, professional standards and requirements, what else may be a form of external governance imposed on an organisation
CONTRACTUAL REQUIREMENTS
41
Enterprise Governance
If an organisation has a hierarchical structure in place i.e. specific departments in place to carry out roles and responsibilities, it can be said to have what sort of structure
FUNCTIONAL
41
Enterprise Governance
All different organisational structures in the business, from lower level work sections to higher level departments and divisions, have “what” in regards to cybersecurity
RESPONSIBILITIES
- Information security is everyones responsibility
42
Enterprise Governance
Information security governance is most effective when every person knows what about their role
WHAT IS EXPECTED OF THEM
- Better organisations develop formal roles and responsibilities so that personnel have a clear idea of their part in all matters related to the protection of information systems
42
Enterprise Governance
“A description of the expected activities that an employee is obligated to perform as part of their employment”
What is this a definition of in relation to organisational roles
ROLE
42
Enterprise Governance
“Roles are typically associated with this label, the label being assigned to each person that designates their place in the organisation”
What is this a definition of in relation to organisational roles
JOB TITLE
42