CCSP Domain 6: Policies, Standards, Baselines and Guidelines Flashcards
What is a policy?
broad statement of management intent
Is policy compliance mandatory?
yes
What are the generalized statements about the cybersecurity objective included in information security policy?
- stetement of importance of cybersecurity to the organization
- requirements that all staff and contracts take measures to protect the confidentiality, integrity and availability of information and information systems
- statement of the ownership of information created and/or possessed by the organization
- designation of CISO or other individual as the executive responsible for cybersecurity issues
- delegation of authority granting the CISO the ability to create standards, procedures and guidelines that implement the policy
Who approves policies?
CEO; requires approval from senior management
What should cybersecurity managers do when developing new security policies in the relation to the already existing policy development mechanisms?
should align their work with any other policy development mechanisms that may exist within their organization; aligning with existing procedures makes it easier for the new initiative to track action
What key principles should be followed by cybersecurity managers when working on policy development initiatives? (4)
- obtain input from all relevant stakeholders
- follow the chain of command
- accomodate the organizational structure
- meet internal and external requirements
Do security policies contain prescriptive technical guidance, such as a requirement to use a specific encryption algorithm?
no, this type of detail would normally be found in a security standard
All policies within the organization should include a section that includes which elements?
- policy maintenance
- policy enforcement
- policy enforcement
The baseline should cover what systems?
as many systems throughout the organization as possible; more systems that are included in the baseline, the more cost-effective and scalable the baseline is
What do standards provide?
mandatory requirements describing how an organization will carry out its information security policies; may include specific configuration settings used for OS’es
Who approves standards in an organization?
standards are usually approved at lower organizational level than policies, thus they change more frequently
What are procedures?
detailed, step-by-step processes that individuals and organizations must follow; ensure consistent process for achieving a security objective
Is compliance with procedures mandatory?
yes
What is the purpose of guidelines?
provide best practices and recommendations related to a given concept, technology or task
Is compliance with guidelines mandatory?
no, it aims to serve as a helping hand