Chapter 11 Flashcards
Transitioning
with a business partner occurs either during the on-boarding or off boarding of a business partner
397
SLA
Service Level Agreement
Determines response time
BPO
Blanket Purchase Order
Agreement between a gov agency and private company for ongoing purchases of goods and services
Risk Awareness
Organizations both communicating with each other to share information regarding risks
MOU
Memorandum of Understanding
Document is used in many settings in the information industry. It is a brief summary of which party is responsible
ISA
Interconnection Security Agreement
Agreement between two organizations that have connected systems in regards to technical security
Organization training
Importance of Security Responsibilities of people in the organization Policies and proceedures Usage policies Account and password selection criteria Social engineering prevention
Management training
global issues in the organization including enforcing security policies and proceedures
Technical staff training
needs special knowledge about the methods implimentations and capabilities of the systems used to manage security
Safety concerns
Fencing Lighting Locks CCTV Escape Plans Drills Escape rooms Testing controls
Clean desk policy
Information on the desk: printouts, pads of paper, sticky notes can be seen by prying eyes
Compliance with laws, best practices and standards
Users need to realize that working with data is the same as driving a car: there are best practices and standards of which you must adhere
Data Handling
Only users needing to work with it should have access to data
Policy on Personal Devices
Don’t let people bring their personal devices into secure places because they’re dumbasses
Tailgating
Following someone into a secure environment after they open it up