5.3 Organizational Security Policies Flashcards
Define acceptable use policy
Provides rules for how organization technology can be used
Security benefit of job rotation
Prevents discovery of security risks by one person doing a specific task for too long
Security benefit of mandatory vacations (3)
- Allows another person to make sure everything is functioning as expected
- Limits ability of one person to commit a fraud
- Not common, typically only found in very high security environments
Define separation of duties
Completing a task requires the knowledge of 2 people and helps prevent breaches initiated by a single person
Security benefit of clean desk policy
Employees must secure sensitive information before leaving their desk to prevent access to it by an unauthorized party
Define capture the flag
Competition for red team to practice their skills and try to breach a system
Security risks with third-parties (4)
- Must evaluate the security of any third-parties provided information or access
- Vendors
- Supply chain
- Business partners
Define memorandum of understanding (MOU)
An informal letter that is not a binding contract but sets forth expectations of both parties
Define measurement systems analysis (MSA) (2)
- Used as part of a quality management system, such as Six Sigma
- A process for ensuring that the processes that produce data used as the basis for important decisions is accurate
Define business partnership agreement (BPA) (4)
A document outlining the details of business partnership including:
1. Owners stakes
2. Financial stakes
3. Decision makers
4. Contingency plans
Define end of life (EOL)
A vendor stops selling a product but continues to provide updates & patches
Define end of service life (EOSL)
End of life except vendor also stops providing updates & patches
Define steward and data management (2)
- Organizations must have processes and procedures in place to manage data securely and in accordance with laws/regulations
- Steward is person/group in charge of this data governance and classification
Define governance relative to data management
Setting procedures and policies regarding organizational data including classification and retention
Define classification relative to data management
Classifying data that is subject to laws/regulations to ensure proper handling by the organization