1 - Security Influences and Risk Flashcards
Advisory Security Policy
Provides instruction on acceptable and unacceptable activities
Informative Security Policy
Provides information from an education standpoint
Risk management involves:
identification, assessment, analyzation, and mitigation of risks
Measurement of information security issues at management levels is accomplished by what?
The risk management framework
What do risk profiles represent?
a cross-section of an organization’s comfort level of which risks it will and will not tolerate
Risk management measure the effect of security on what?
business objectives
Security practitioner must consider what objectives?
business and security
What is NIST?
a U.S. government agency that develops a formal series of special publications that detail policies, procedures, and guidelines for the security of federal computer devices.
The NIST Risk Management Framework (RMF) is detailed in what publication?
NISP SP 800-39: Managing Information Security Risk
The NIST Risk Management Framework (RMF) includes what stages related to security controls?
- Categorize
- Select
- Implement
- Assess
- Authorize
- Monitor
What is ISO?
ISO is the world’s largest standards organization; it creates standard for many industries, including security and technology
What organizations are able to provide official accreditation to organization for demonstrating compliance with particular standard and guidelines?
NIST and ISO
Many partnership business models involve the exchange of information, making information security requirements what?
a cross-business issue
With regard to personnel, business models influence what?
how personnel are employed and whether to rely on in-house expertise or offshore talent
What are the two high-level types of partnerships?
formal and informal
Partners share in what?
operational responsibility, profits, and liabilities associate with a business
Policies associate with the user of information by a partner should be?
determined in advance and provided to customer(s) for approval
Customer data cannot be shared with other parties without:
notification of business purpose and (in the EU) customer consent, aka opt-in
Cloud computing helps organizations in what ways?
Reducing costs and improving productivity by utilizing applications, accessibility, storage, availability, and scalability
Prior to signing an agreement with a cloud provider, organizations must do what?
Determine the risk management and assessment processes the cloud provider implements
Reviewing service level agreements allows you to learn what?
the service offerings and promises of a cloud, outsourcing, or other provider
As businesses become global what practice with regard to personnel is becoming more common?
outsourcing of business functions, including information security activities