01. Intro to Sec Governance Flashcards
Intro to Sec Governance
What is GOVERNANCE
Senior management exrts strategic control over business functions through
1. policies
2. objectives
3. delegation of authority
4. monitoring
33
Intro to Sec Governance
How is governance usually established
Steering committees
33
Intro to Sec Governance
9 typical processes that information security GOVERNANCE focuses on
- Personnel Management
- Sourcing
- Risk Management
- Configuration Management
- Change Management
- Access Management
- Vulnerability Management
- Incident Management
- Business Continuity P.anning (BCP)
Intro to Sec Governance
Organisations not adequately protecting their information through an information security program have a ____ problem
Business Problem
34
Intro to Sec Governance
A lack of understanding and committment by these parties is typically the reason why business have a problem protecting their information
The most typical reason why a business will have a problem implementing or putting in place an information security program to protect their information
Board of directors and Senior Management
34
Intro to Sec Governance
When information security becomes a people issue and people from each level in the organisation understand the importance, the organisation will be in a position of what
Reduced Risk
34
Intro to Sec Governance
reduction in risk results in;
1. Fewer ____
2. When they do occur, have lower ____
3. This is felt on the organisations ____ and ____
- Incidents
- Impact
- Reputation and Operations
34
Intro to Sec Governance
Information Security Governance is a set of established activities that helps management understand the state of the organisations ____, its current ____, and its direct ____
- security program
- risks
- activities
34
Intro to Sec Governance
A goal of the ____ is to continue to contribute toward the fulfilment of the security strategy
Security Program
34
Intro to Sec Governance
The security strategy will continue to align with the ____
Business and Business Objectives
34
Intro to Sec Governance
What does GOVERNANCE begin with establishing, that is translated into actions, policies, processes, procedures, and other activities down through the levels of the organisation
Top-Level Strategic Objectives
34
Intro to Sec Governance
What other program must an organisation have in place in order for the information security governance to succeed
Effective IT Governance Program
34
Intro to Sec Governance
What is the purpose of security governance
Align SECURITY PROGRAM with the NEEDS OF THE BUSINESS
35
Intro to Sec Governance
A collection of top-down activities intended to control the security of the organisation from a strategic perspective
Information Security Governance
35
Intro to Sec Governance
Desired capabilities or end states are ideally expressed in achievable, measureable terms
Artifacts and actions that flow out of a healthy security governance program
Objectives
35