02. Organisational Culture Flashcards
Organisational Culture
A term that describes how people within an orgnisation treat one another and how they get things done
Organisational Culture
39
Organisational Culture
Every organisation has this, and it affects how the organisation deals with risk and how it treats risk over time
Risk Culture
39
Organisational Culture
2 things in relation to risk that support the organisation risk culture
Risk Tolerance and Risk Appetite
39
Organisational Culture
A formal policy statement that defines permitted activities and forbidden activities in an organisation
Acceptable Use Policy
(AUP)
39
Organisational Culture
A policy which defines acceptable or forbidden use of company information and assets and their handling and use of
Acceptable Use Policy
(AUP)
39
Organisational Culture
2 key reasons that organisations require users to acknowledge, often in writing (digitally) that they have read and will comply with an acceptable use policy (AUP)
- Emphasises importance
- Non-repudiation
Non-repudiation - employee cannot later claim they did not know about a policy
39
Organisational Culture
One:
Supporting and complying with standards and procedures for ____ and ____ of information systems and technology
ISACA Code of Profession Ethics
Governance and Management
40
Organisational Culture
Two
Performing duties professionally, with ____ and ____ as required by professional standards
ISACA Code of Profession Ethics
Due Dilligence and Care
40
Organisational Culture
Three
Conducting activities in a lawful manner and maintaining the ____ of conduct and ____ required by the profession and ISACA
ISACA Code of Profession Ethics
High Standards and Character
40
Organisational Culture
Four
Ensuring ____ and ____ of sensitive information obtained in the course of professional duties
ISACA Code of Profession Ethics
Privacy and Confidentiality
40
Organisational Culture
Five
Maintaining ____ in the professional field
ISACA Code of Profession Ethics
Competency
40
Organisational Culture
Six
____ and ____ regarding results of work performed to ensure that the results of that work are not distored
ISACA Code of Profession Ethics
Full Disclosure and Impartiality
40
Organisational Culture
Seven
Supporting professional education in the areas of ____ and ____ of enterprise infomration systems and technology, to include auditing, controls, security, and risk management
ISACA Code of Profession Ethics
Governance and Management
40