01. Intro to Sec Governance Flashcards

1
Q

Intro to Sec Governance

What is GOVERNANCE

A

Senior management exrts strategic control over business functions through
1. policies
2. objectives
3. delegation of authority
4. monitoring

33

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Intro to Sec Governance

How is governance usually established

A

Steering committees

33

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Intro to Sec Governance

9 typical processes that information security GOVERNANCE focuses on

A
  1. Personnel Management
  2. Sourcing
  3. Risk Management
  4. Configuration Management
  5. Change Management
  6. Access Management
  7. Vulnerability Management
  8. Incident Management
  9. Business Continuity P.anning (BCP)
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Intro to Sec Governance

Organisations not adequately protecting their information through an information security program have a ____ problem

A

Business Problem

34

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Intro to Sec Governance

A lack of understanding and committment by these parties is typically the reason why business have a problem protecting their information

The most typical reason why a business will have a problem implementing or putting in place an information security program to protect their information

A

Board of directors and Senior Management

34

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Intro to Sec Governance

When information security becomes a people issue and people from each level in the organisation understand the importance, the organisation will be in a position of what

A

Reduced Risk

34

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Intro to Sec Governance

reduction in risk results in;
1. Fewer ____
2. When they do occur, have lower ____
3. This is felt on the organisations ____ and ____

A
  1. Incidents
  2. Impact
  3. Reputation and Operations

34

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Intro to Sec Governance

Information Security Governance is a set of established activities that helps management understand the state of the organisations ____, its current ____, and its direct ____

A
  1. security program
  2. risks
  3. activities

34

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Intro to Sec Governance

A goal of the ____ is to continue to contribute toward the fulfilment of the security strategy

A

Security Program

34

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Intro to Sec Governance

The security strategy will continue to align with the ____

A

Business and Business Objectives

34

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Intro to Sec Governance

What does GOVERNANCE begin with establishing, that is translated into actions, policies, processes, procedures, and other activities down through the levels of the organisation

A

Top-Level Strategic Objectives

34

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Intro to Sec Governance

What other program must an organisation have in place in order for the information security governance to succeed

A

Effective IT Governance Program

34

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Intro to Sec Governance

What is the purpose of security governance

A

Align SECURITY PROGRAM with the NEEDS OF THE BUSINESS

35

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Intro to Sec Governance

A collection of top-down activities intended to control the security of the organisation from a strategic perspective

A

Information Security Governance

35

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Intro to Sec Governance

Desired capabilities or end states are ideally expressed in achievable, measureable terms

Artifacts and actions that flow out of a healthy security governance program

A

Objectives

35

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Intro to Sec Governance

A plance to achieve one or more objectives

Artifacts and actions that flow out of a healthy security governance program

A

Strategy

35

16
Q

Intro to Sec Governance

At its minimum, this should directly reflect the mission, objectives, and goals of the overall organisation

Artifacts and actions that flow out of a healthy security governance program

A

Policy

35

17
Q

Intro to Sec Governance

These should flow directly from the organisations mission, objectives and goals. Whatever is most important to the organisation should also be essential to information security

Artifacts and actions that flow out of a healthy security governance program

A

Priorities

35

18
Q

Intro to Sec Governance

These help drive a consistent approach to solving business challenges. The choice of these should facilitate solutions that meet the organisations needs in a cost-effective and secure manner

Artifacts and actions that flow out of a healthy security governance program

A

Standards

35

19
Q

Intro to Sec Governance

Formalised descriptions of repeated business activities inlcuding instructions to applicable personnel.

Artifacts and actions that flow out of a healthy security governance program

A

Processes

35

20
Q

Intro to Sec Governance

Formal descriptions of critical activities to ensure desired outcomes

Artifacts and actions that flow out of a healthy security governance program

A

Controls

35

21
Q

Intro to Sec Governance

These should be organised and performed in a consistent manner that reflects the business priorities and supports the business

Artifacts and actions that flow out of a healthy security governance program

A

Programs and project management

35

22
Q

Intro to Sec Governance

Formal measurements of processes and controls so that management understands and can measure them

Artifacts and actions that flow out of a healthy security governance program

A

Metrics / Reporting

35

23
Q

Intro to Sec Governance

What 2 things must the information security manager understand withn the business concerning confidentiality, integrity, and availability (CIA)

A

Appetite and priority

36

24
Q

Intro to Sec Governance

Management will ensure that risk assessments are performed to identify risks in information systems and supported processes

Activities required to protect the organisation which senior management will ensure are in place to support the business operations

A

Risk Management

36

25
Q

Intro to Sec Governance

Management will ensure this activity is conducted when key changes are made which result in security improvements

Activities required to protect the organisation which senior management will ensure are in place to support the business operations

A

Process Improvement

36

26
Q

Intro to Sec Governance

Management will put technologies and processes in place to ensure that security incidents will be identified as quickly as possible

Activities required to protect the organisation which senior management will ensure are in place to support the business operations

A

Event Identification

36

27
Q

Intro to Sec Governance

Management will put this in place to reduce the impact and probability of incidents, and improve response capabilities to minimize their impact

Activities required to protect the organisation which senior management will ensure are in place to support the business operations

A

Incident response

36

28
Q

Intro to Sec Governance

Management will identify all applicable laws, regulations and standards and carry out activities to confirm the organisation and attain and maintain compliance

Activities required to protect the organisation which senior management will ensure are in place to support the business operations

A

Improved Compliance

37

29
Q

Intro to Sec Governance

Management define objectives and allocate resources to develop a plan in the event of major business disruption

Activities required to protect the organisation which senior management will ensure are in place to support the business operations

A

Business Continuity and Disaster Recoery Planning

37

30
Q

Intro to Sec Governance

Management will establish processes to measure key security events such as incidents, policy changes and violations, audits, and training

Activities required to protect the organisation which senior management will ensure are in place to support the business operations

A

Metrics

37

31
Q

Intro to Sec Governance

The allocation of workforce, budget, and other elements to meet the security objectives

Activities required to protect the organisation which senior management will ensure are in place to support the business operations

A

Resource Management

37

32
Q

Intro to Sec Governance

An effective security governance program will resul tin better strategic decisions in IT organisation that keep risks at an acceptably low level

Activities required to protect the organisation which senior management will ensure are in place to support the business operations

A

Improved IT Governance

37

33
Q

Intro to Sec Governance

The 2 key results of an effective security governance program

A

Increased Trust
Customers, suppliers etc. trust the organisation more when they see security is managed effectively
Improved Reputation
Business community will hold the organisation in higher regard

37

34
Q

Intro to Sec Governance

An organisations information security program needs to do what with the rest of the organisation

A

Align

37

35
Q

Intro to Sec Governance

To be business aligned, people in the security program need to be aware of and understand the 5 following components

A
  1. Culture
  2. Asset Value
  3. Risk Tolerance (appetite)
  4. Legal Obligations
  5. Market Conditions

38

36
Q

Intro to Sec Governance

The term used to define a scenario where individuals or groups bypass corporate IT and procure their own computing services putting the organisation at a greater risk of data leakage

A

Shadow IT

38

37
Q

Intro to Sec Governance

The level of risk that an organisation is willing to accept while pursuing its mission, strategy, and objectives before taking action to treat the risk

A

Risk Appetite