1.7 Develop, Document, and Implement Security Policies, Procedures, Standards, Baselines, and Guidelines. Flashcards

1
Q

What Group should be in Charge of Designing Security Policies for the Board of Directors and CEO?

A

Governance Committee. This should include an overarching security policy that aligns with the organizations goals and objectives for the security function.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What are policies in a corporate sense?

A

Policies are corporate laws that reflect the goals and objectives of an organization. They dictate and communicate management’s intentions.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Why is an overarching security policy critical for an organization?

A

It sets the tone and helps create the culture necessary for effective organization security to exist.This policy should be consistently communicated, especially from upper managment.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

An simple overarching security policy must do what?

A

Clearly express that the board and CEO are accountable while all everyone in the organization are responsible for security and protecting the value of assets.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Why should an overarching security policy be simple and effective?

A

To ensure the security function is seen as an enabler and a helper, as opposed to the traditional view of security as an obstacle. [For instance, when a team is told they can’t do something because of security risks]

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What should flow from an overarching policy?

A

Specific funtional security policies.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What makes up a functional security policy?

A

Standards | Procedures | Baselines | Guidelines

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

TRUE or FALSE:
Policies need to be reviewed yearly to ensure effectiveness.

A

FALSE: Policies do not need to be every year, but standards, procedures, baselines, and guidelines may need to be updated regularly.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

How do Overarching and Functional Policies Differ? How are functional policies supported?

A

Overarching policies are a generalized idea of the organizations goals and objectives | Functional policies are unique policies aimed to build upon the goals of the overarching policies | Functional Policies are made up of standards, baselines, procedures, and guideliens to support the goal of the Functional Policy.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Using an Anti-Malware Mandate as an example of a Funcitonal Policy, explain how standards, guidelines, baselines, and procedure can support this functional policy.

A

A standard can specify the version of anti-malware software to use | a procedure can outline the steps to install it | and a guidelines to suggest ideal goals for anti-malware efforts, such as hueristics in anti-malware software where possible.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What are aspects of a Policy?

A

Documents that communicate management’s goals and objectives | Provide authority to security activity | Define the elements, functions, and scope of the security team | Must be approved and communicated | Considered corporate law

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What are Standards in Relation to Policies?

A

Specific hardware and software solutions, mechanisms, and products. Includes: Specific anti-virus software, specific access control systems, specific firewalls, and published guidelines adopted as an organization standard.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What are Procedures in Relation to Policies?

A

Step-by-step instruction on how to perform a task; mandatory actions. Includes: User registration or new hire onboarding, contracting for security purposes, Information system material desctruction, incident response.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What are Baselines in Relation to Policies?

A

Defined minimal implementation methods/levels for a security mechanism and product. Includes: Configurations for intrusion detection systems and configurations for access controls.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What are Guidelines in Relation to Policies?

A

Recommended and Suggested actions. Includes: Government recommendations, security configuration recommendations, organization guidelines, and product/sytem evaluation criteria. (Note: Guidelines allow an organization to suggest something be done without making it a hard requirement and thus case a negative audit finding)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly