6.4 Protection Measures Flashcards

1
Q

Staff responsibilities

A

Staff of an organisation will spend most time handling and amending data so the company must have sufficient and effective protection measures in place so that:

staff are confident in their role and know their responsibilities of information security

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Staff responsibilities (2)

A

Certain staff members may be responsible for types of data within an organisation e.g confidential data so:

Assigning specific people to roles ensures that they know what their job is and that they are responsible if data is lost

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Staff responsibilities (3)

A

Organisations need to consider which members of staff have access rights to creating information

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Staff responsibilities (3) (question)

Why do organisations need to consider this?

A

As if data is confidential then:

More people that have access to that data, the higher the risk of it being lost or tampered with

Sensitive data: accessed by those who need to use it as part of their job

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Staff responsibilities (4)

Why should staff be trained?

A

So they know how to adequately handle information including:

Data security techniques

How to protect data from unauthorised access and loss

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Disaster & Recovery planning

What are disasters?

A

Natural disasters

Hardware failure

Software failure

Malicious damage

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Disaster & Recovery planning

Before the disaster

A

All possible risks to be analysed for preparation

Preventative measures e.g flood-proof or storing data in a different area

Staff training to inform employees on what to do in the event of a disaster

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Disaster & Recovery Planning

During the disaster

A

Staff response is important, employees should follow their training, ensuring that data is protected and measures are put in place

Contingency plans such as uploading recent data to cloud storage or security backups

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Disaster & Recovery planning

After the disaster

A

Recovery measures such as backups

Replacement hardware purchased for equipment that is corrupted or destroyed

Software needs to be reinstalled on new hardware

Disaster recovery policies should be updated and improved

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Assessments and Effectiveness

What should organisations conduct and why?

A

Information security risk assessments to ensure that their physical and logical measures are up-to-date and that they provide the most effective methods of protection.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Assessments and Effectiveness

Why test security measures in place?

A

Identify any weak-points and fix those highlighted vulnerabilities to minimise the extent of external and internal data intrusion

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Assessments and Effectiveness

Why implement training drills for the staff?

A

To provide the staff with experience on:

What should happen if a disaster or:

Substantial data loss occurs so:

That the company is prepared

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Organisations security assessment may identify specific cost impact

These are necessary financial expenditures to ensures the security of data and systems such as:

A

Software - firewalls to be purchased for protected network systems

Hardware - buying secure storage devices and new computer systems

Training - hiring industry experts to train staff on how to keep data secure

Security - hiring staff to protect server rooms

How well did you know this?
1
Not at all
2
3
4
5
Perfectly