(8) Guidelines And Exceptions Flashcards

1
Q

In terms of an information security program, what are guidelines?

A

Guidelines are best practices, but aren’t required to happen, they are provided in the spirit of being helpful

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What else should orgs include in their policy and guideline documents?

A

There should be a process of exceptions and compensating controls. These are out of the ordinary situations where an approved deviation from the normal way of doing things should happen

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What should compensating control procedures include?

A

Compensating control procedures should include what standard provides for the situation, the justification for why the process or procedure is not going to be followed, risks, description of other controls that will be put in place, and identification of any unmitigated risks

How well did you know this?
1
Not at all
2
3
4
5
Perfectly