04. Information Security Policies, Procedures, and Guidelines Flashcards

1
Q

Information Security Policies, Procedures, and Guidelines

Information security policies, standards, guidelines, and procedures are the written artifacts that define…

A

the business and technical rules for information and information systems protection

222

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Policy Development

Defines the principles and required actions for the organisation to protect its assets and personnel properly

A

Information Security Policy

222

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Policy Development

The audience for security policy is the organisations personnel, which includes…

A

all workers, not just full time, but temporary, contractors, and consultants

222

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Policy Development

4 key considerations that the development of policy should include…

A
  1. Laws, regulations, standards, legal obligations
  2. Risk tolerance
  3. Controls
  4. Organisational Culture

222

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Policy Development

Security policy and controls need to be in alignment. Policies and controls must not…

A

contradict each other

222

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Policy Development

Security policy needs to align with the audience, meaning that policy statements need to be…

A

understood by workers

A common mistake is developing security policies with the inclusion of highly technical detail that would not be easily understood by non technical people

222

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Policy Development

Policy statements should state…

A

what needs to be done, not how

Security policies should be general and not cite specific devices, technologies etc..

223

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Policy Development

Security policy statements should be general and not cite specific devices, technologies, algorithms, or configurations. This will esnure that policies will be…

A

durable and not need to be changed frequently

223

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Policy Development

In comparison to security policy statements, security standards and procedure documents may need to change more frequently as..

A

practices, techniques and technologies change

223

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Standards

Where a policy states “what to do”, a standard describes…

A

how to do it or what to do

224

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Guidelines

Guidelines are nonbinding statements or narratives that provide additional direction to personnel regarding compliance with…

A

security policies, standards, and controls

224

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Requirements

A formal statement that describes the characteristics of a system that is to be changed, developed, or acquired

A

Requirements

224

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Requirements

Requirements should flow from, and align with…

A

the structure and content of policies and standards

224

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Requirements

Requirements must be…

A

specific and verifiable

Ambiguity should be resolved, there needs to be a clear understanding of each requirement

224

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Requirements

Requirements should be used in a step-by-step procedure for verifying that a system, service, or process complies with said requirements. Therefore, requirements can be considered a basis for…

A

a valid test plan

In testing, do we meet all the requirements?

224

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Requirements

Project managers and subject matter experts should prioritize requirements to distinguish….

A

those that are “must haves” v’s those that are “nice to have”

225

17
Q

Requirements

Some organisations distinguish function requirements from nonfunctional requirements.

  1. Nonfunctional requirements define what a system…
  2. Functional requirements define what a system…
A
  1. Is supposed to BE
  2. Is supposed to DO

225

18
Q

Processes and Procedures

Processes and procedures are detailed, sequenced instructions used to complete routine tasks and ensure….

A

consistency and compliance with individual policies and controls

225

19
Q

Processes and Procedures

A collection of one or more procedures that together fulfil a higher purpose

A

Process

225

20
Q

Processes and Procedures

A written set of instructions for a single task

A

Procedure

225

21
Q

Processes and Procedures

Auditors regard process and procedure documents to be outdated and invalid if…

A

they have not been reviewed for more than one year

225