5.1 Policies, plans and procedures related to organizational security Flashcards
BPA
Business partners agreement
SLA
(service level agreement) Operating procedures and standards for a service contract.
ISA
(interconnection security agreement) A business agreement that focuses on ensuring security between organizations in a partnership. Any federal agency interconnecting its IT system to a third party must create an ISA to govern the relationship. An ISA sets out a security risk awareness process and commits the agency and supplier to implementing security controls.
MOU/MOA
(Memorandum of Understanding) Usually a preliminary or exploratory agreement to express an intent to work together.
Job rotation
Means that no one person is permitted to remain in the same job for an extended period.
Separation of duties
A means of establishing checks and balances against the possibility that critical systems or procedures can be compromised by insider threats.
Data owner
A senior (executive) role with ultimate responsibility for maintaining the confidentiality, integrity, and availability of the information asset.
System administrator
The day-to-day sysadmin role requires technical understanding of access controls and privilege management systems.
System owner
This role is responsible for designing and planning computer, network, and database systems. The role requires expert knowledge of IT security and network design.
Privileged user
Employees with access to privileged data should be given extra training on data management and PII plus any relevant regulatory or compliance frameworks.
Executive user
Good security awareness is essential as these users are likely to be specifically targeted (whale phishing and spear phishing).
Continuing education
Ensures that the participants do not treat a single training course or certificate as a sort of final accomplishment. Skills and knowledge must be continually updated to cope with changes to technology and regulatory practices.
Adverse actions
Means that in disciplining or firing an employee, the employer is discriminating against them in some way.