8. Operations: Training and Awareness Flashcards

1
Q

What risk mitigating tests can incident response teams preform?

A
  1. Incident response testing
  2. Red team testing
  3. Threat intel sharing
  4. Data loss prevention
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What accounts for 67% of data breach events?

A

Credential theft, social attacks (phishing), business email compromises, and administrative errors.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Are the majority of incidents internal or external?

A

70% are external

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What is the most common method of breach attack?

A

Attacking web applications through stolen credentials (80%) or brute force credentials

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What is the difference between training and awareness?

A

Training - strives to produce relevant and needed skills and competencies

Awareness - focuses on a specific topic such as security

*NIST SP 800-50: “The most significant difference between training and awareness is that training seeks to teach skills, which allow a person to preform a specific function, while awareness seeks to focus an individual’s attention on an issue or set of issues”

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Is training a regulatory requirement?

A

Yes, it is a key control with most privacy regulations.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What must privacy training address?

A
  1. Applicable laws and policies
  2. Identify potential violations
  3. Address privacy complaints and misconduct
  4. Include proper reporting procedures and consequences for violations
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

To whom internal training extend to?

A

Business partners and vendors.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What should trainees be required to acknowledge?

A

That they received training and agree to abide by company policies and applicable law.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What functions do training and awareness serve?

A

Training - communicates the organizations privacy message, policies and procedures, including those for data usage and retention, access control and incident reporting

Awareness - reinforces the privacy message through reminders, continued advertisement, and mechanisms such as quizzes, posters, flyers, and lobby video screens

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What should be considered when privacy breaches occur?

A
  1. Leverage lessons learned from events that make the headlines
  2. Use mistakes as learning opportunities to improve process
  3. Use stories
  4. Hold lunch and learn sessions
  5. Make it fun
  6. Develop slogans that can be used in presentations to capture the essence of the message
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What methods can lead to the development and execution of an effective training and awareness plan?

A
  1. Ingrain operational accountability
  2. Ensure a holistic data protection view
  3. Allow for the incorporation of compliance requirement changes
  4. Identify, catalog, and maintain all document requirements update as privacy requirements change
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What is the most effective targeted training effort?

A

Where the privacy office spends time with the business unit’s leader to learn about risk areas and modifies the training or presentation accordingly.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What should the intention behind training and awreness?

A

Changing bad behaviours and reinforcing good ones.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What are some training and awareness methods?

A
  1. Formal education
  2. E-learning
  3. Brown bag and department team meeting
  4. Newsletters, emails, and posters
  5. Handouts
  6. Slogans and comics
  7. Internal social media page
  8. Webpages
  9. Hallways or lobby monitors to broadcast
  10. Contests
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Why are training metrics useful?

A

They show how the privacy program supports the company’s mission and prove to regulators they are actively addressing compliance risks