1. Information Security Governance - 24% Flashcards
What is a RACI Chart
Responsible
Accountable
Consultable
Informed
What are the 5 principles of the National Association of Corporate Directors
Principle 1 - cybersecurity is an enterprise-wide issue
Principle 2 - Understand legal implications of cyber risks
Principle 3 - access to cybersecurity expertise
Principle 4 - boards should set expectations that management will establish an enterprise wide cyber risk management framework
Principle 5 - should discuss cyber risk including avoidance, acceptance, mitigation and transfer.
What are different types of metrics used for simple categorization
Key Risk Indicators - metrics associated with risk with measurement of risks
Key Goal Indicators - attainment of strategic goals
Key Performance Indicators - show efficiency and effectiveness of security-related goals
What is ROSI
Return on Security Investment.
What is the acronym SMART in the effective ness of a metric
Specific
Measurable
Attainable
Relevant
Timely
What is BMIS
Developed by ISACA in 2009 the Business Model for Information Security is a guide for business aligned risk-based security governance.
This was derived from the Systemic Security Management Framework developed by USC Marshal School of Business
What is the dominant enterprise architecture standard established in the late 80s
The Zachman Framework
starts with a high functional level and then in increasing details.
What does the Zachman model do not do for IT Systems
It does not convey the relationships between IT System. Data Flow Diagrams are used to depict that.
What is the difference between a leading indicator and trailing indicator
leading indicators are a predictor of the probability of future security incidents. Patch Management Stats, Phishing Sim Results, UEBA, etc.
Trailing indicators are more reactive in nature based on security incidents related to attacks blocked by firewall, viruses stopped, etc.
What are the elements of the business model for information security (BMIS)
Organization, people, process and technology.
The dynamic interconnections (DI’s) are culture, governing architecture, emergence, enabling and support, and human factors.
the Primary Factor to the selection of a control framework is
Industry Vertical - for example a healthcare organization is going to want to utilize HIPAA Security Rules
What is the purpose of a balanced scorecard?
Measure organizational performance and effectiveness against strategic goals.
tool used to quantify the performance of an organization against strategic objectives
A process that is performed consistently but it is not documented is generally considered to be
Repeatable
T or F all processe should reach the maturity level of optimized
False - there are no rules that the maturity levels of different processed need to be the same or at a different level.
What is the primary responsibility of the custodial related to customers
Custodian makes decisions based on customer’s defined interests