07. Information Security Program Communications and Reporting (349) Flashcards

1
Q

Security Operations

Security Operations needs to write reports with target audience in mind

349

A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Security Operations

Security Manager needs to maintain effective relationships with business units

350

A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Security Operations

Security manager examins security clauses in legal contracts to ensure they can be met

350

A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Human Resources

Human Resources important role in organisational security

351

A

Recruiting
Onboarding
Internal Transfers
Offboarding
Training
Investigations
Discipline

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Human Resources

Human Resource Information System (HRIS) integrates with IAM systems

351

A

Recruiting
Onboarding
Internal Transfers
Offboarding
Training
Investigations
Discipline

352

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Facilities

Facilities manage services, processes, and functions that contribute to security

352

A

Workplace acces control
Workplace surveillance
Equipment check-in/check-out
Guest processing
Security guards
Asset Security
Personnel safety

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Information Technology

Many key functions performed by IT with security ramifications

354

A

Access Control
Architecture
Configuration Hardening
Scanning and patching
Security tools
System monitoring
Security monitoring
Third party connections

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Systems Development

Systems Development manages product development life cycle that integrates security at each stage of the life cycle

354

A

Security and privacy by design
Secure Development
Security testing
Code Reviews
Security review of open source software
Developer training
Protection of the development process

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Procurement

Procurement manager can notify security manager on purchase of new hardware/software enabling security manage to perform due dilligence

355

A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Business Unit Managers

Security managers need to establish good relationships with business managers to understand how the business functions and understand processes

355

A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Key Business Partners

Many securtiy breaches are connected with third parties. Development of strategic relationships with 3rd parties is essential

356

A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

External Partnerships

Security manager must establish relationship with key external organisations

A

Law enforcement
Regulators and Auditors
Standards Organisations
Profession Organisations
Security Professional Services Vendors
Securtiy Product Vendors

258

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Compliance Management

Security Managers need to report on organisations compliance with policies, standards, regulations, and cybersecurity legal obligations

359

A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Compliance vs Security

Organisations fall into one or two categories;

Compliance Based
Tick box organisation. Bare minimum possible to pass audit
Security and Risk Based
Organisation understands external standards and use this to develop activities and controls to be more secure

359

A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Compliance Applicability

Security Managers should build compliance matrix to determine applicability of regulations and standards.
Organisations overspend without reducing risk if only applying requirements for regulations and legal requirements

359

A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Compliance Risk

Compliance risk - general or specific consequences of non compliance with law or legal obligation

360

A
17
Q

Compliance Enforcement

Security managers report on state of compliance to senior management
Non compliance risks reflected in metrics as higher risks

360

A
18
Q

Retaining Talent

Organisations have the challenge of retaining skilled and knowledgeable cyber professionals.
Must have a right balance between security manager doing “cool new things” and aligning those needs of satisfaction to business needs

361

A
19
Q

Roles and Responsibilities

Role - A designation. Denotes associated set of responsibilities, knowledge, skills, attitudes
Responsibility - Stated expectation of activities and performance

362

A

Role - Security Manager
Responsibility - Effective manage the organistaions security program

20
Q

Professional Development

Security managers - encourage team members to earn certifications
Invest in team members, develop and understand career paths

364

A