04. Information Security Policies, Procedures, and Guidelines Flashcards
Information Security Policies, Procedures, and Guidelines
Information security policies, standards, guidelines, and procedures are the written artifacts that define…
the business and technical rules for information and information systems protection
222
Policy Development
Defines the principles and required actions for the organisation to protect its assets and personnel properly
Information Security Policy
222
Policy Development
The audience for security policy is the organisations personnel, which includes…
all workers, not just full time, but temporary, contractors, and consultants
222
Policy Development
4 key considerations that the development of policy should include…
- Laws, regulations, standards, legal obligations
- Risk tolerance
- Controls
- Organisational Culture
222
Policy Development
Security policy and controls need to be in alignment. Policies and controls must not…
contradict each other
222
Policy Development
Security policy needs to align with the audience, meaning that policy statements need to be…
understood by workers
A common mistake is developing security policies with the inclusion of highly technical detail that would not be easily understood by non technical people
222
Policy Development
Policy statements should state…
what needs to be done, not how
Security policies should be general and not cite specific devices, technologies etc..
223
Policy Development
Security policy statements should be general and not cite specific devices, technologies, algorithms, or configurations. This will esnure that policies will be…
durable and not need to be changed frequently
223
Policy Development
In comparison to security policy statements, security standards and procedure documents may need to change more frequently as..
practices, techniques and technologies change
223
Standards
Where a policy states “what to do”, a standard describes…
how to do it or what to do
224
Guidelines
Guidelines are nonbinding statements or narratives that provide additional direction to personnel regarding compliance with…
security policies, standards, and controls
224
Requirements
A formal statement that describes the characteristics of a system that is to be changed, developed, or acquired
Requirements
224
Requirements
Requirements should flow from, and align with…
the structure and content of policies and standards
224
Requirements
Requirements must be…
specific and verifiable
Ambiguity should be resolved, there needs to be a clear understanding of each requirement
224
Requirements
Requirements should be used in a step-by-step procedure for verifying that a system, service, or process complies with said requirements. Therefore, requirements can be considered a basis for…
a valid test plan
In testing, do we meet all the requirements?
224