Anki - Organization Security 3 Flashcards
What is Personnel Management?
The practice of ensuring all of an organization’s internal and external personnel complies with policy.
What are the three phases of a Personnel Management Policy?
Recruitment
Operation
Termination
What department is tasked with managing personnel?
HR
What are some operational policies of personnel management?
Communication of policies to employees E.g.
- Privilege management
- Data handling
- Incident response
- Also enforcement of disciplinary measures
What are 5 security tasks when onboarding a new employee?
- Background check
- Identity and access management (IAM)
- Sign an NDA
- Asset allocation (laptop)
- Training/policies
What is Separation of Duties?
Separation of duties states that no one person should have too much power or responsibility.
It is a way to protect against inside threats.
What is Shared Authority? What is it an example of?
No single user is able to make changes on their own. At least two people must authorize the change.
An example of a Separation of Duties Policy.
What is Least Privilege? What is it an example of?
A user is granted sufficient rights to perform their job and no more. For critical tasks, duties are divided between several people.
An example of a Separation of Duties Policy.
What are mandatory vacations? Why are they useful?
Forced vacations - they are useful to discover any discrepancies in employee activity once they are away.
What is job rotation? Why is it useful?
Employees must rotate job roles.
E.g. Firewall Administrator or Access Control Specialist.
Prevents abuse of power, reduces boredom and enhances employee’s skills!
What are the three processes for off-boarding an employee?
- IAM - Disable user account and privileges
- Retrieve company assets - keys, laptops etc.
- Wipe personal assets of company data
Maybe also change credentials to shared security systems, if that person had access.
What is a conduct policy?
A policy that defines employee conduct and respect for privacy.
What is an AUP?
Acceptable Use Policy, or Fair Use Policy sets what someone is allowed to use a particular service or resource for.
E..g what a company laptop may be used for.
How can allowing employees unrestricted access to the internet in a workplace be a problem?
Use of social networking and file sharing can put an organization at risk of:
- virus infection
- systems intrusion
- lost work time
- copyright infringement
- defamation
The organization could be liable.
What should be included in an employee’s handbook?
What browser/email/social networking/P2P software is permitted for personal use.
And what penalties exist.