Anki - Organizational Security Flashcards

1
Q

What is a policy?

A

Policy is an overall statement of intent.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What are the main goals of a corporate security policy?

A
  • To gain security awareness in the organization.
  • To outline the risks, guidelines, and responsibilities.
  • To demonstrate that due care and diligence has been applied.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What are the three “mechanisms” of a security policy?

A
  • Standard
  • Procedure or SOP (Standard Operating Procedure)
  • Guidance
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Why are an organization’s security policies important?

A
  • Set the tone for employee attitudes towards security
  • Set standards for completing work
  • Policies may also be shared with partners/customers
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What is a “standard” when referring to security policies?

A

A standard is a measure by which to evaluate compliance with the policy.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What is a “procedure” or “SOP” when referring to security policies?

A

A Standard Operating Procedure (SOP), is an inflexible, step-by-step listing of the actions that must be completed for any given task. Most critical tasks should be governed by SOPs.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What is a “guidance” when referring to security policies?

A

Guidelines exist for procedures that do not have a policy or describe circumstances where it is appropriate to deviate from a specified procedure.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What is an Interoperability Agreement?

A

An agreement between a company and any third party vendors.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Why are Interoperability Agreements important?

A

A company is responsible for the services/actions a third party vendors might make. A security breach in their org, (e.g. data leak) is a breach of your own.

An agreement outlines the shared duties and contractual responsibilities.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What are the 6 common types of Interoperability Agreements?

A
  1. Memorandum of understanding (MOU)
  2. Memorandum of agreement (MOA)
  3. Service level agreement (SLA)
  4. Business partners agreement (BPA)
  5. Interconnection security agreement (ISA)
  6. Non-disclosure agreement (NDA)
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What is an MOU?

A

Memorandum of understanding (MOU)

  • A preliminary or exploratory agreement to express an intent to work together.
  • Usually informal and not binding contracts.
  • MOUs usually have clauses requesting mutual confidentiality.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What is an MOA?

A

Memorandum of agreement (MOA)

  • A formal agreement (or contract)
  • Outlines specific obligations.
  • If one party fails to fulfill its obligations, the other party will be able to seek legal redress.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What is an SLA?

A

Service level agreement (SLA)

- A contractual agreement setting out the detailed terms under which a service is provided.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What is a BPA?

A

Business partners agreement (BPA)

Most common with large IT companies and their resellers and solution providers. e.g. Microsoft and Cisco.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What is an ISA?

A

Interconnection security agreement (ISA)

  • Federal agencies connecting their system with a third party must create an ISA to govern the relationship.
  • An ISA sets out a security risk awareness process and commits the agency and supplier to implementing security controls.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

How does NIST define an ISA?

A

ISAs are defined by NIST’s SP800-47 as “Security Guide for Interconnecting Information Technology Systems”

17
Q

What is an NDA?

A

Non-disclosure agreement (NDA)

  • Legal basis for protecting information assets
  • Used between companies and employees, companies and contractors, and two companies.
18
Q

Why is data security more important in today’s world?

A

Greater volumes of data are now stored and accessed in many locations, so organizations must consider not only the physical access to data storage systems, but also the devices that access them.