CHAPTER 15 Flashcards
To ensure that a suitable level of security is maintained, management
must follow up the implementation with an evaluation of the effectiveness of the security controls
T
Management controls refer to issues that management needs to address
T
Operational controls range from simple to complex measures that work
together to secure critical and sensitive data, information, and IT systems functions
F
Detection and recovery controls provide a means to restore lost
computing resources
T
Water damage protection is included in security controls
T
All controls are applicable to all technologies
F
Physical access or environmental controls are only relevant to areas
housing the relevant equipment.
T
Once in place controls cannot be adjusted, regardless of the results of
risk assessment of systems in the organization
F
Controls may vary in size and complexity in relation to the
organization employing them.
T
It is likely that the organization will not have the resources to
implement all the recommended controls
T
The selection of recommended controls is not guided by legal
requirements.
F
The recommended controls need to be compatible with the
organization’s systems and policies
T
The implementation phase comprises not only the direct
implementation of the controls, but also the associated training and general security awareness programs for the organization
T
Appropriate security awareness training for all personnel in an
organization, along with specific training relating to particular systems and controls, is an essential component in implementing controls
T
The IT security management process ends with the implementation of
controls and the training of personnel
F