10: 4 Security Policies Flashcards

1
Q

Security Policy Framework (4)

A

Policies, Standards, Guidelines, Procedures

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Security Policies

A

Provide foundation for a security program, carefully written, require compliance from all employees, are approved at the highest levels of the org

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Security Standards

A

Provide specific details of security controls, derive authority from policies, require compliance from all employees

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Security Guidelines

A

Provide security advice to the organization, follow best practices from industry, not mandatory

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Security Procedures

A

Outline a step-by-step process for an activity, may require compliance

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Data Security Policy Criteria

A

Foundational Authority for Data Security Efforts, Clear Expectations for data security responsibilities, guidance for requesting access to information, process for granting policy exceptions

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Data Storage Policies

A

Appropriate locations, access control requirements, encryption requirements,

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Data Transmission Policies

A

Protect data in motion, covering encryption requirements and acceptable transmission mechanisms

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Data lifecycle policies

A

Describe end of life for data (data retention policies - how long data elements are kept, data disposal policies - how to destroy data that’s no longer needed)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly