Chapter 11 - Security Administration Flashcards
What is a SLA?
page 398
Service Level Agreement
Defines the level of service to be provided.
What is BPO?
page 398
Blanket Purchase Order
An Agreement between a government agency and a private company for ongoing purchases of goods or services.
What is MOU?
page 398
Memorandum of Understanding
Brief summary of which party is responsibility for what portion of the work.
What is ISA?
page 398
Interconnection Security Agreement
What kind of training involves everyone understanding policies, procedures and resources available to deal with security problems?
page 399
Organization
Ideally what security awareness should Organization training cover?
page 400
- Importance of security
- Responsibilities of people in the organization
- Policies and procedures
- Usage policies
- Account and password-selection criteria
- Social engineering prevention
Who receives additional training or exposure that explains the issues, threats and methods of dealing with threats and will want want to know the hows and whys of security training?
page 400
Management
Who receives special knowledge training about methods. implementation and capabilities of the systems used to manage security?
page 400
Technical Staff
What are some of the topics relate to the safety of the data or physical environment?
page 401
- Fencing - CCTV
- Lighting - Escape Plans
- Locks - Drills
- Escape Routes - Testing Controls
Why is it important to have a clean desk policy?
page 402
Information on the desk can easily be seen by prying eyes and taken by thieving hands.
What is P2P?
page404
Peer-to-peer
What is PII?
page 404
Personally Identifiable Information
Is a catchall for any data that can be used to uniquely identify an individual.
How does NIST define PII?
page 404
Any information about an individual maintained by an agency, including
1. Any information that can be used to distinguish or trace an individual’s identity, such as name, social security number, date and place of birth, mother’s maiden name or biometrics records.
2. Any other information that is linked to an individual, such as medical, education, financial and employment information.
What is piggybacking?
page 405
Where the individual knowingly allows another person to tailgate behind hime.
What are one safe internet habit?
page 406
Never download or install from unknown sites.