Anki - Organizational Security Flashcards
What is a policy?
Policy is an overall statement of intent.
What are the main goals of a corporate security policy?
- To gain security awareness in the organization.
- To outline the risks, guidelines, and responsibilities.
- To demonstrate that due care and diligence has been applied.
What are the three “mechanisms” of a security policy?
- Standard
- Procedure or SOP (Standard Operating Procedure)
- Guidance
Why are an organization’s security policies important?
- Set the tone for employee attitudes towards security
- Set standards for completing work
- Policies may also be shared with partners/customers
What is a “standard” when referring to security policies?
A standard is a measure by which to evaluate compliance with the policy.
What is a “procedure” or “SOP” when referring to security policies?
A Standard Operating Procedure (SOP), is an inflexible, step-by-step listing of the actions that must be completed for any given task. Most critical tasks should be governed by SOPs.
What is a “guidance” when referring to security policies?
Guidelines exist for procedures that do not have a policy or describe circumstances where it is appropriate to deviate from a specified procedure.
What is an Interoperability Agreement?
An agreement between a company and any third party vendors.
Why are Interoperability Agreements important?
A company is responsible for the services/actions a third party vendors might make. A security breach in their org, (e.g. data leak) is a breach of your own.
An agreement outlines the shared duties and contractual responsibilities.
What are the 6 common types of Interoperability Agreements?
- Memorandum of understanding (MOU)
- Memorandum of agreement (MOA)
- Service level agreement (SLA)
- Business partners agreement (BPA)
- Interconnection security agreement (ISA)
- Non-disclosure agreement (NDA)
What is an MOU?
Memorandum of understanding (MOU)
- A preliminary or exploratory agreement to express an intent to work together.
- Usually informal and not binding contracts.
- MOUs usually have clauses requesting mutual confidentiality.
What is an MOA?
Memorandum of agreement (MOA)
- A formal agreement (or contract)
- Outlines specific obligations.
- If one party fails to fulfill its obligations, the other party will be able to seek legal redress.
What is an SLA?
Service level agreement (SLA)
- A contractual agreement setting out the detailed terms under which a service is provided.
What is a BPA?
Business partners agreement (BPA)
Most common with large IT companies and their resellers and solution providers. e.g. Microsoft and Cisco.
What is an ISA?
Interconnection security agreement (ISA)
- Federal agencies connecting their system with a third party must create an ISA to govern the relationship.
- An ISA sets out a security risk awareness process and commits the agency and supplier to implementing security controls.