(8) Policies Flashcards

1
Q

What are policies?

A

Policies are high level statements of management intent

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What is an information security policy?

A

An information security policy provides a high level authority and guidance for the security system of the company

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is an acceptable use policy (AUP)?

A

AUP provides network and system users with clear direction of useful and allowed action with information resources

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What is a data ownership policy?

A

Data ownership states that ownership of information created or used is owned by the company

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What is a data classification policy?

A

Data classification is one that describes how the company classifies data and the process that properly assigns data classification

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What is a data retention policy?

A

The data retention policy lays out what info the org will maintain and the length of time different categories of work will be retained prior to destruction

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What is an account management policy?

A

An account management policy is about the account life cycle starting from provisioning, to active use, and decommissioning

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What is a password policy?

A

A password policy puts forth requirements for password length, how complex they are, how they are reused (not reused), etc

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What is a continuous monitoring policy?

A

Continuous monitoring policy describes the orgs approach to monitoring and informs employees that their activity will be tracked

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What is a code of conduct policy?

A

Code of conduct policy describes how employees are expected to behave and it serves as a structure for situations not addressed as well

How well did you know this?
1
Not at all
2
3
4
5
Perfectly