04. Info Sec Gov: Policies, procedures, guidelines, and frameworks Flashcards
Policies, procedures, guidelines, and frameworks
Policies
- Mandatory
- High Level, non specific
- May contain patches, updates, strong encryption
- Will not be specific to OS or encryption type, vendor technology
- Strategic, typically delivered by C-Level
Policies, procedures, guidelines, and frameworks
Standards
- Mandatory
- Specific use of technology
- All windows laptops will be windows 10 for example, 64bit, 8 gig mem
- Management level typically involved here
- Tactical
Policies, procedures, guidelines, and frameworks
Guidelines
- Non-Mandatory
- Recommendations, discretionary
- Suggests how something could be implemented
- Tactical
Policies, procedures, guidelines, and frameworks
Procedures
- Mandatory
- Low level step by step
- Will contain OS and encryption type, vendor technology
- Tactical
Policies, procedures, guidelines, and frameworks
Baseline
- Mandatory
- Minimum requirements
Policies, procedures, guidelines, and frameworks
Personnel Security
Users pose largest security risk
Policies, procedures, guidelines, and frameworks
Personnel Security:
Awareness
Change user behaviour
Policies, procedures, guidelines, and frameworks
Personnel Security:
Training
Provide users with skillset
Policies, procedures, guidelines, and frameworks
Personnel Security:
Hiring Practices
Background checks
Policies, procedures, guidelines, and frameworks
Personnel Security:
Employee Termination Practices
Coach and Train employees before firing
Coordinate with HR
Policies, procedures, guidelines, and frameworks
Personnel Security:
Vendors, Consultants, Contractor
- Ensure outsiders are train how to handle data
- Their systems need to be secure in accordance with our policy
Policies, procedures, guidelines, and frameworks
Personnel Security:
Outsourcing and Offshoring
- A 3rd party doing all or in part your IT work
- Perform thorough risk anlysis
- Offshoring - may not have to comply with same data protection standards
- Outsource - someone else close by
- Offshoring - someone else far away