1: Auditing Security Management Flashcards

1
Q

Auditing security management activities require attention to keys such as

A
  • Policies, processes, procedures, and standards
  • Records
  • Security awareness training
  • Data ownership and management
  • Data custodians
  • Security administrators
  • New and existing employees
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Policies, processes, procedures, and standards

A

The auditor should request and examine information security policies to see what processes are required. This should be followed by requests to examine process and procedure documentation for key processes that are cited in security policies.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Records

A

the auditor should examine business records to see whether processes are active.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Security awareness training

A

The auditor should examine training materials, training procedures, and training records to determine the effectiveness of the organization’s security awareness training program.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Data ownership and management

A

The IS auditor should inquire about the methodology used to determine ownership and management of business data. The key point with data ownership and management is accountability:

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Data custodians

A

the IS auditor should identify whether data custodians effectively carry out the wishes of the data owner, or act on their own as if they are the owner.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Security administrators

A

The IS auditor should determine if IT staff are knowledgeable about these duties and qualified to carry them out.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

New and existing employees

A

The IS auditor should determine if any policies exist on this topic and whether security awareness training covers this theme.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly