(8) Guidelines And Exceptions Flashcards
In terms of an information security program, what are guidelines?
Guidelines are best practices, but aren’t required to happen, they are provided in the spirit of being helpful
What else should orgs include in their policy and guideline documents?
There should be a process of exceptions and compensating controls. These are out of the ordinary situations where an approved deviation from the normal way of doing things should happen
What should compensating control procedures include?
Compensating control procedures should include what standard provides for the situation, the justification for why the process or procedure is not going to be followed, risks, description of other controls that will be put in place, and identification of any unmitigated risks