Chapter 1 Flashcards

1
Q

What are the 3 groups/communities of interest involved in information security decisions?

A
  • InfoSec: protect the organizations assets from threats.
  • IT: supplying and supporting IT appropriate to the business’ needs.
  • General business: Communicating organizational policies and allocating resources to the other groups.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What’s the role of management

A

to ensure that security strategies are properly planned and controlled.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What’s Management?

A

It’s achieving objectives using the available resources.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What’s a manager?

A

A manager is assigned to administrate resources and coordinate tasks, to achieve objectives.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What are the 3 managerial roles?

A
  • Informational role: Collecting, and processing information.
  • Interpersonal role: Interacting with parties that affect the completion of the task.
  • Decisional role: decision making and resolving conflicts.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What’s the difference between leadership and management?

A

A leader leads by example to influence employees to accomplish objectives.

A manager is assigned to administrate resources and coordinate tasks, to achieve objectives.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

3 behavioral types of leaders:

A

– The Autocratic: taking no account of other people’s wishes or opinions.

– The Democratic: taking into consideration other’s wishes or opinions.

– The Laissez-faire: let others operate according to their own laws.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

2 basic approaches to management are:

A

– Traditional management theory (POSDC): Staffing/Directing.

– Popular management theory (POLC): more emphasis on leading than directing.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

3 Categories of Planning:

A

– Strategic planning: 5+ Years.

– Tactical planning: 1 - 5 Years.

– Operational planning: day-to-day operations.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What’s “Governance”?

A

The practices of the management to achieve goals and manage risks.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

5 steps to solving problems:

A
  • Step 1: Define problem.
  • Step 2: Gather information.
  • Step 3: Develop Possible Solutions
  • Step 4: Compare Possible Solutions.
  • Step 5: Choose and evaluate a solution.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Unique functions of information security
management are known as the six P’s:

A

– Planning
– Policy
– Programs
– Protection
– People
– Project Management

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

“Policy” is:

A

guidelines for behavior in an organization.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

3 general categories of policy:

A

– Enterprise information security policy (EISP)

– Issue-specific security policy (ISSP).

– System-specific policies (SysSPs)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

3 examples of the many InfoSec plans are:

A

– incident response planning.
– disaster recovery planning.
– risk management planning.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly