5.3 Organizational Security Policies Flashcards

1
Q

Define acceptable use policy

A

Provides rules for how organization technology can be used

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Security benefit of job rotation

A

Prevents discovery of security risks by one person doing a specific task for too long

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Security benefit of mandatory vacations (3)

A
  1. Allows another person to make sure everything is functioning as expected
  2. Limits ability of one person to commit a fraud
  3. Not common, typically only found in very high security environments
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Define separation of duties

A

Completing a task requires the knowledge of 2 people and helps prevent breaches initiated by a single person

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Security benefit of clean desk policy

A

Employees must secure sensitive information before leaving their desk to prevent access to it by an unauthorized party

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Define capture the flag

A

Competition for red team to practice their skills and try to breach a system

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Security risks with third-parties (4)

A
  1. Must evaluate the security of any third-parties provided information or access
  2. Vendors
  3. Supply chain
  4. Business partners
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Define memorandum of understanding (MOU)

A

An informal letter that is not a binding contract but sets forth expectations of both parties

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Define measurement systems analysis (MSA) (2)

A
  1. Used as part of a quality management system, such as Six Sigma
  2. A process for ensuring that the processes that produce data used as the basis for important decisions is accurate
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Define business partnership agreement (BPA) (4)

A

A document outlining the details of business partnership including:
1. Owners stakes
2. Financial stakes
3. Decision makers
4. Contingency plans

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Define end of life (EOL)

A

A vendor stops selling a product but continues to provide updates & patches

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Define end of service life (EOSL)

A

End of life except vendor also stops providing updates & patches

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Define steward and data management (2)

A
  1. Organizations must have processes and procedures in place to manage data securely and in accordance with laws/regulations
  2. Steward is person/group in charge of this data governance and classification
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Define governance relative to data management

A

Setting procedures and policies regarding organizational data including classification and retention

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Define classification relative to data management

A

Classifying data that is subject to laws/regulations to ensure proper handling by the organization

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Define retention relative to data management

A

Ensuring that data is retained in accordance with laws/regulations and the organization’s requirements