(8) Policies Flashcards
What are policies?
Policies are high level statements of management intent
What is an information security policy?
An information security policy provides a high level authority and guidance for the security system of the company
What is an acceptable use policy (AUP)?
AUP provides network and system users with clear direction of useful and allowed action with information resources
What is a data ownership policy?
Data ownership states that ownership of information created or used is owned by the company
What is a data classification policy?
Data classification is one that describes how the company classifies data and the process that properly assigns data classification
What is a data retention policy?
The data retention policy lays out what info the org will maintain and the length of time different categories of work will be retained prior to destruction
What is an account management policy?
An account management policy is about the account life cycle starting from provisioning, to active use, and decommissioning
What is a password policy?
A password policy puts forth requirements for password length, how complex they are, how they are reused (not reused), etc
What is a continuous monitoring policy?
Continuous monitoring policy describes the orgs approach to monitoring and informs employees that their activity will be tracked
What is a code of conduct policy?
Code of conduct policy describes how employees are expected to behave and it serves as a structure for situations not addressed as well